CVE-2024-39947: Medium severity dahuasecurity nvr4104-4ks2/l firmware vulnerability
A vulnerability has been found in Dahua products.After obtaining the ordinary user's username and password, the attacker can send a carefully crafted data packet to the interface with vulnerabilities, causing the device to crash.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39947?
CVE-2024-39947 is considered to be a critical vulnerability due to the potential for device crashes following unauthorized access.
How do I fix CVE-2024-39947?
To mitigate CVE-2024-39947, update the firmware of affected Dahua devices to the latest version provided by the manufacturer.
Which devices are affected by CVE-2024-39947?
Affected devices include specific Dahua NVR models, such as NVR4104-4KS2/L, NVR4108-4KS2/L, and several others referenced in the firmware details.
How can an attacker exploit CVE-2024-39947?
An attacker can exploit CVE-2024-39947 by sending a specially crafted data packet after obtaining valid user credentials.
What are the consequences of exploiting CVE-2024-39947?
Exploiting CVE-2024-39947 can lead to a device crash, resulting in potential downtime and loss of functionality for the affected Dahua products.