Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-824h-6hr6-ghh3

Опубликовано: 27 дек. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

Some Dahua software products have a vulnerability of unauthenticated un-throttled ICMP requests on remote DSS Server. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could exploit the victim server to launch ICMP request attack to the designated target host.

Some Dahua software products have a vulnerability of unauthenticated un-throttled ICMP requests on remote DSS Server. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could exploit the victim server to launch ICMP request attack to the designated target host.

EPSS

Процентиль: 44%
0.00213
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-287
CWE-770

Связанные уязвимости

CVSS3: 5.9
nvd
около 3 лет назад

Some Dahua software products have a vulnerability of unauthenticated un-throttled ICMP requests on remote DSS Server. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could exploit the victim server to launch ICMP request attack to the designated target host.

EPSS

Процентиль: 44%
0.00213
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-287
CWE-770