IT

Tracker / CVE-2022-45434

CVE-2022-45434

Medium 5.9

Some Dahua software products have a vulnerability of unauthenticated un-throttled ICMP requests on remote DSS Server. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could exploit the victim server to launch ICMP request attack to the designated target host.

Affected products and versions

dahuasecurity dhi-dss4004-s2_firmware
dahuasecurity dhi-dss7016d-s2_firmware
dahuasecurity dhi-dss7016dr-s2_firmware
dahuasecurity dss_express
dahuasecurity dss_professional

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References