Dahuasecurity
Dahuasecurity DSS Express: vulnerabilidades y CVE
Dahuasecurity DSS Express tiene 12 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE12
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-45434 | Media (5.9) | 0.66% | — | 27 dic 2022 | Some Dahua software products have a vulnerability of unauthenticated un-throttled ICMP requests on remote DSS Server. After bypassing the firewall access control policy, by sending a specific crafted packet to the… |
| CVE-2022-45433 | Baja (3.7) | 0.63% | — | 27 dic 2022 | Some Dahua software products have a vulnerability of unauthenticated traceroute host from remote DSS Server. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable… |
| CVE-2022-45432 | Media (5.3) | 0.70% | — | 27 dic 2022 | Some Dahua software products have a vulnerability of unauthenticated search for devices. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker… |
| CVE-2022-45431 | Alta (7.5) | 0.64% | — | 27 dic 2022 | Some Dahua software products have a vulnerability of unauthenticated restart of remote DSS Server. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an… |
| CVE-2022-45430 | Baja (3.7) | 0.41% | — | 27 dic 2022 | Some Dahua software products have a vulnerability of unauthenticated enable or disable SSHD service. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface,… |
| CVE-2022-45429 | Alta (7.5) | 0.53% | — | 27 dic 2022 | Some Dahua software products have a vulnerability of server-side request forgery (SSRF). An Attacker can access internal resources by concatenating links (URL) that conform to specific rules. |
| CVE-2022-45428 | Baja (2.7) | 0.68% | — | 27 dic 2022 | Some Dahua software products have a vulnerability of sensitive information leakage. After obtaining the permissions of administrators, by sending a specific crafted packet to the vulnerable interface, an attacker can… |
| CVE-2022-45427 | Alta (7.2) | 0.70% | — | 27 dic 2022 | Some Dahua software products have a vulnerability of unrestricted upload of file. After obtaining the permissions of administrators, by sending a specific crafted packet to the vulnerable interface, an attacker can… |
| CVE-2022-45426 | Media (6.5) | 0.58% | — | 27 dic 2022 | Some Dahua software products have a vulnerability of unrestricted download of file. After obtaining the permissions of ordinary users, by sending a specific crafted packet to the vulnerable interface, an attacker can… |
| CVE-2022-45425 | Alta (7.5) | 0.53% | — | 27 dic 2022 | Some Dahua software products have a vulnerability of using of hard-coded cryptographic key. An attacker can obtain the AES crypto key by exploiting this vulnerability. |
| CVE-2022-45424 | Media (5.3) | 0.68% | — | 27 dic 2022 | Some Dahua software products have a vulnerability of unauthenticated request of AES crypto key. An attacker can obtain the AES crypto key by sending a specific crafted packet to the vulnerable interface. |
| CVE-2022-45423 | Alta (7.5) | 0.57% | — | 27 dic 2022 | Some Dahua software products have a vulnerability of unauthenticated request of MQTT credentials. An attacker can obtain encrypted MQTT credentials by sending a specific crafted packet to the vulnerable interface (the… |
Otros productos de Dahuasecurity
DSS Professional · 12Dhi-dss4004-s2 Firmware · 12Dhi-dss7016d-s2 Firmware · 12Dhi-dss7016dr-s2 Firmware · 12Nvr4816-16p-4ks2/i Firmware · 8Nvr4816-4ks2/i Firmware · 8Nvr4832-16p-4ks2/i Firmware · 8Nvr4416-4ks2/i Firmware · 8Nvr4416-16p-4ks2/i Firmware · 8Nvr4432-16p-4ks2/i Firmware · 8Nvr4432-4ks2/i Firmware · 8Nvr4832-4ks2/i Firmware · 8