Vulnerabilities > Dahuasecurity

DATE CVE VULNERABILITY TITLE RISK
2022-12-27 CVE-2022-45433 Unspecified vulnerability in Dahuasecurity products
Some Dahua software products have a vulnerability of unauthenticated traceroute host from remote DSS Server.
network
high complexity
dahuasecurity
3.7
2022-12-27 CVE-2022-45434 Unspecified vulnerability in Dahuasecurity products
Some Dahua software products have a vulnerability of unauthenticated un-throttled ICMP requests on remote DSS Server.
network
high complexity
dahuasecurity
5.9
2022-06-28 CVE-2022-30560 Unspecified vulnerability in Dahuasecurity products
When an attacker obtaining the administrative account and password, or through a man-in-the-middle attack, the attacker could send a specified crafted packet to the vulnerable interface then lead the device to crash.
network
high complexity
dahuasecurity
7.4
2022-06-28 CVE-2022-30561 Unspecified vulnerability in Dahuasecurity products
When an attacker uses a man-in-the-middle attack to sniff the request packets with success logging in, the attacker could log in to the device by replaying the user's login packet.
network
high complexity
dahuasecurity
5.9
2022-06-28 CVE-2022-30562 Open Redirect vulnerability in Dahuasecurity products
If the user enables the https function on the device, an attacker can modify the user’s request data packet through a man-in-the-middle attack ,Injection of a malicious URL in the Host: header of the HTTP Request results in a 302 redirect to an attacker-controlled page.
network
high complexity
dahuasecurity CWE-601
4.7
2022-06-28 CVE-2022-30563 Unspecified vulnerability in Dahuasecurity products
When an attacker uses a man-in-the-middle attack to sniff the request packets with success logging in through ONVIF, he can log in to the device by replaying the user's login packet.
network
high complexity
dahuasecurity
7.4
2022-01-13 CVE-2021-33046 Improper Authentication vulnerability in Dahuasecurity products
Some Dahua products have access control vulnerability in the password reset process.
network
low complexity
dahuasecurity CWE-287
critical
9.8
2021-09-15 CVE-2021-33044 Improper Authentication vulnerability in Dahuasecurity products
The identity authentication bypass vulnerability found in some Dahua products during the login process.
network
low complexity
dahuasecurity CWE-287
critical
9.8
2021-09-15 CVE-2021-33045 Improper Authentication vulnerability in Dahuasecurity products
The identity authentication bypass vulnerability found in some Dahua products during the login process.
network
low complexity
dahuasecurity CWE-287
critical
9.8
2020-05-13 CVE-2020-9502 Use of Insufficiently Random Values vulnerability in Dahuasecurity products
Some Dahua products with Build time before December 2019 have Session ID predictable vulnerabilities.
network
low complexity
dahuasecurity CWE-330
critical
9.8