IT

Tracker / CVE-2022-45432

CVE-2022-45432

Medium 5.3

Some Dahua software products have a vulnerability of unauthenticated search for devices. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could unauthenticated search for devices in range of IPs from remote DSS Server.

Affected products and versions

dahuasecurity dhi-dss4004-s2_firmware
dahuasecurity dhi-dss7016d-s2_firmware
dahuasecurity dhi-dss7016dr-s2_firmware
dahuasecurity dss_express
dahuasecurity dss_professional

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References