CVE-2022-45433: Low severity dahua security dhi-dss7016d-s2 firmware vulnerability
Some Dahua software products have a vulnerability of unauthenticated traceroute host from remote DSS Server. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could get the traceroute results.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this Dahua software vulnerability?
The vulnerability ID for this Dahua software vulnerability is CVE-2022-45433.
What is the severity of CVE-2022-45433?
The severity of CVE-2022-45433 is low.
Which products are affected by CVE-2022-45433?
Some Dahua software products, including Dahuasecurity Dhi-dss7016d-s2 Firmware, Dahuasecurity Dhi-dss7016dr-s2 Firmware, and Dahuasecurity Dss Express, are affected by CVE-2022-45433.
How can an attacker exploit CVE-2022-45433?
An attacker can exploit CVE-2022-45433 by bypassing the firewall access control policy and sending a specific crafted packet to the vulnerable interface to retrieve traceroute results.
Is Microsoft Windows affected by CVE-2022-45433?
No, Microsoft Windows is not affected by CVE-2022-45433.