Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2632▼ 307 respecto a la semana anterior
Críticas / altas1348▲ 75 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
–

6 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.3%—Dahuasecurity Ipc-hx1xxx FirmwareDahuasecurity Ipc-hx2xxx FirmwareDahuasecurity Ipc-hx3xxx FirmwareDahuasecurity Ipc-hx5(4)(3)xxx Firmware+2413/1/202217/6/2026
Some Dahua products have access control vulnerability in the password reset process. Attackers can exploit this vulnerability through specific deployments to reset device passwords.
AnalizadaCrítica (9.8)100%⚠ Explotación activaDahuasecurity Ipc-hum7xxx FirmwareDahuasecurity Ipc-hx3xxx FirmwareDahuasecurity Ipc-hx5xxx FirmwareDahuasecurity Sd1a1 Firmware+1515/9/202117/6/2026
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.
ModificadaCrítica (9.8)1.5%—Dahuasecurity Sd6al FirmwareDahuasecurity Sd5a FirmwareDahuasecurity Sd1a FirmwareDahuasecurity Ptz1a Firmware+1613/5/202017/6/2026
Some Dahua products with Build time before December 2019 have Session ID predictable vulnerabilities. During normal user access, an attacker can use the predicted Session ID to construct a data packet to attack the device.
ModificadaAlta (8.1)0.86%—Dahuasecurity Sd6al FirmwareDahuasecurity Sd5a FirmwareDahuasecurity Sd1a FirmwareDahuasecurity Ptz1a Firmware+1613/5/202017/6/2026
Dahua devices with Build time before December 2019 use strong security login mode by default, but in order to be compatible with the normal login of early devices, some devices retain the weak security login mode that users can control. If the user uses a weak security login method, an attacker can monitor the device…
ModificadaMedia (4.9)1.0%—Dahuasecurity Sd6al FirmwareDahuasecurity Sd5a FirmwareDahuasecurity Sd1a FirmwareDahuasecurity Ptz1a Firmware+159/4/202017/6/2026
Some products of Dahua have Denial of Service vulnerabilities. After the successful login of the legal account, the attacker sends a specific log query command, which may cause the device to go down.
ModificadaAlta (7.2)1.5%—Dahuasecurity Sd6al FirmwareDahuasecurity Sd5a FirmwareDahuasecurity Sd1a FirmwareDahuasecurity Ptz1a Firmware+159/4/202017/6/2026
Some Dahua products have buffer overflow vulnerabilities. After the successful login of the legal account, the attacker sends a specific DDNS test command, which may cause the device to go down.