CVE-2022-45434: Medium severity dahua security dhi-dss7016d-s2 firmware vulnerability
Some Dahua software products have a vulnerability of unauthenticated un-throttled ICMP requests on remote DSS Server. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could exploit the victim server to launch ICMP request attack to the designated target host.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-45434?
CVE-2022-45434 is a vulnerability found in some Dahua software products that allows unauthenticated un-throttled ICMP requests on remote DSS Server.
Which software products are affected by CVE-2022-45434?
The affected software products include Dahuasecurity Dhi-dss7016d-s2 Firmware versions 1.001.0000001.2, 8.0.2, 8.0.4, and 8.1, as well as Dahuasecurity Dss Express versions 7.002.1760000.2, 8.0.2, 8.0.4, 8.1, and 8.1.1.
What is the severity of CVE-2022-45434?
CVE-2022-45434 has a severity rating of 5.9, which is considered medium.
How can an attacker exploit CVE-2022-45434?
An attacker can exploit CVE-2022-45434 by bypassing the firewall access control policy and sending a specific crafted packet to the vulnerable interface, allowing them to launch ICMP requests on the victim server.
Where can I find more information about CVE-2022-45434?
More information about CVE-2022-45434 can be found on the Dahua Security website at https://www.dahuasecurity.com/support/cybersecurity/details/1137.