CVE-2024-39948: Input Validation
A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities, causing the device to crash.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39948?
The vulnerability CVE-2024-39948 is classified as critical due to the potential for device crashes caused by specially crafted data packets.
How do I fix CVE-2024-39948?
To mitigate CVE-2024-39948, update the affected Dahua devices to the latest firmware version provided by the manufacturer.
Which Dahua products are affected by CVE-2024-39948?
CVE-2024-39948 affects multiple Dahua NVR models, including NVR4104-4KS2/L and NVR4116-4KS2/L, specifically those running firmware versions prior to 4.003.0000000.1.r.240515.
Can CVE-2024-39948 be exploited remotely?
Yes, CVE-2024-39948 can be exploited remotely without the need for physical access to the device.
What symptoms indicate a system affected by CVE-2024-39948?
Devices affected by CVE-2024-39948 may experience unexpected crashes or reboots when vulnerable data packets are sent to them.