Vulnerabilities > Dahuasecurity

DATE CVE VULNERABILITY TITLE RISK
2020-05-13 CVE-2020-9501 Unspecified vulnerability in Dahuasecurity web P2P
Attackers can obtain Cloud Key information from the Dahua Web P2P control in specific ways.
local
low complexity
dahuasecurity
5.5
2020-05-13 CVE-2019-9682 Incorrect Default Permissions vulnerability in Dahuasecurity products
Dahua devices with Build time before December 2019 use strong security login mode by default, but in order to be compatible with the normal login of early devices, some devices retain the weak security login mode that users can control.
network
high complexity
dahuasecurity CWE-276
8.1
2020-04-09 CVE-2020-9500 Unspecified vulnerability in Dahuasecurity products
Some products of Dahua have Denial of Service vulnerabilities.
network
low complexity
dahuasecurity
4.9
2020-04-09 CVE-2020-9499 Classic Buffer Overflow vulnerability in Dahuasecurity products
Some Dahua products have buffer overflow vulnerabilities.
network
low complexity
dahuasecurity CWE-120
7.2
2019-09-18 CVE-2019-9680 Unspecified vulnerability in Dahuasecurity products
Some Dahua products have information leakage issues.
network
low complexity
dahuasecurity
5.3
2019-09-18 CVE-2019-9679 Incorrect Default Permissions vulnerability in Dahuasecurity products
Some of Dahua's Debug functions do not have permission separation.
network
low complexity
dahuasecurity CWE-276
8.8
2019-09-18 CVE-2019-9678 Unspecified vulnerability in Dahuasecurity products
Some Dahua products have the problem of denial of service during the login process.
network
low complexity
dahuasecurity
7.5
2019-09-18 CVE-2019-9677 Classic Buffer Overflow vulnerability in Dahuasecurity products
The specific fields of CGI interface of some Dahua products are not strictly verified, an attacker can cause a buffer overflow by constructing malicious packets.
network
low complexity
dahuasecurity CWE-120
critical
9.8
2019-09-17 CVE-2019-9681 Missing Encryption of Sensitive Data vulnerability in Dahuasecurity products
Online upgrade information in some firmware packages of Dahua products is not encrypted.
network
low complexity
dahuasecurity CWE-311
5.3
2019-06-12 CVE-2019-9676 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Dahuasecurity products
Buffer overflow vulnerability found in some Dahua IP Camera devices IPC-HFW1XXX,IPC-HDW1XXX,IPC-HFW2XXX Build before 2018/11.
local
low complexity
dahuasecurity CWE-119
7.8