CVE-2024-39946: High severity dahuasecurity nvr4104-4ks2/l firmware vulnerability
A vulnerability has been found in Dahua products.After obtaining the administrator's username and password, the attacker can send a carefully crafted data packet to the interface with vulnerabilities, causing device initialization.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39946?
The severity of CVE-2024-39946 is assessed as high due to the potential for device initialization following unauthorized access.
How do I fix CVE-2024-39946?
To fix CVE-2024-39946, change the default administrator credentials and apply security patches provided by Dahua.
Which products are affected by CVE-2024-39946?
Products affected by CVE-2024-39946 include various models of Dahua NVRs, specifically those with firmware versions prior to 4.003.0000000.1.r.240515.
What can an attacker do if they exploit CVE-2024-39946?
If exploited, an attacker can send crafted data packets to the device, potentially causing it to reset or malfunction.
How can I determine if my Dahua device is vulnerable to CVE-2024-39946?
To determine if your Dahua device is vulnerable to CVE-2024-39946, check the firmware version against those listed as affected.