Vulnerabilities > Dahuasecurity > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-07-31 CVE-2024-39945 Unspecified vulnerability in Dahuasecurity products
A vulnerability has been found in Dahua products.  After obtaining the administrator's username and password, the attacker can send a carefully crafted data packet to the interface with vulnerabilities, causing the device to crash.
network
low complexity
dahuasecurity
4.9
2024-07-31 CVE-2024-39947 Unspecified vulnerability in Dahuasecurity products
A vulnerability has been found in Dahua products.After obtaining the ordinary user's username and password, the attacker can send a carefully crafted data packet to the interface with vulnerabilities, causing the device to crash.
network
low complexity
dahuasecurity
6.5
2023-06-06 CVE-2023-3121 Server-Side Request Forgery (SSRF) vulnerability in Dahuasecurity Smart Parking Management
A vulnerability has been found in Dahua Smart Parking Management up to 20230528 and classified as problematic.
low complexity
dahuasecurity CWE-918
4.6
2023-02-09 CVE-2022-30564 Unspecified vulnerability in Dahuasecurity products
Some Dahua embedded products have a vulnerability of unauthorized modification of the device timestamp.
network
low complexity
dahuasecurity
5.3
2022-12-27 CVE-2022-45424 Missing Authentication for Critical Function vulnerability in Dahuasecurity products
Some Dahua software products have a vulnerability of unauthenticated request of AES crypto key.
network
low complexity
dahuasecurity CWE-306
5.3
2022-12-27 CVE-2022-45426 Files or Directories Accessible to External Parties vulnerability in Dahuasecurity products
Some Dahua software products have a vulnerability of unrestricted download of file.
network
low complexity
dahuasecurity CWE-552
6.5
2022-12-27 CVE-2022-45432 Unspecified vulnerability in Dahuasecurity products
Some Dahua software products have a vulnerability of unauthenticated search for devices.
network
low complexity
dahuasecurity
5.3
2022-12-27 CVE-2022-45434 Unspecified vulnerability in Dahuasecurity products
Some Dahua software products have a vulnerability of unauthenticated un-throttled ICMP requests on remote DSS Server.
network
high complexity
dahuasecurity
5.9
2022-06-28 CVE-2022-30561 Unspecified vulnerability in Dahuasecurity products
When an attacker uses a man-in-the-middle attack to sniff the request packets with success logging in, the attacker could log in to the device by replaying the user's login packet.
network
high complexity
dahuasecurity
5.9
2022-06-28 CVE-2022-30562 Open Redirect vulnerability in Dahuasecurity products
If the user enables the https function on the device, an attacker can modify the user’s request data packet through a man-in-the-middle attack ,Injection of a malicious URL in the Host: header of the HTTP Request results in a 302 redirect to an attacker-controlled page.
network
high complexity
dahuasecurity CWE-601
4.7