Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-45434

Опубликовано: 27 дек. 2022
Источник: nvd
CVSS3: 5.9
EPSS Низкий

Описание

Some Dahua software products have a vulnerability of unauthenticated un-throttled ICMP requests on remote DSS Server. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could exploit the victim server to launch ICMP request attack to the designated target host.

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:o:dahuasecurity:dhi-dss7016d-s2_firmware:1.001.0000001.2:*:*:*:*:*:*:*
cpe:2.3:o:dahuasecurity:dhi-dss7016d-s2_firmware:8.0.2:*:*:*:*:*:*:*
cpe:2.3:o:dahuasecurity:dhi-dss7016d-s2_firmware:8.0.4:*:*:*:*:*:*:*
cpe:2.3:o:dahuasecurity:dhi-dss7016d-s2_firmware:8.1:*:*:*:*:*:*:*
cpe:2.3:h:dahuasecurity:dhi-dss7016d-s2:-:*:*:*:*:*:*:*
Конфигурация 2

Одновременно

Одно из

cpe:2.3:o:dahuasecurity:dhi-dss7016dr-s2_firmware:1.001.0000001.2:*:*:*:*:*:*:*
cpe:2.3:o:dahuasecurity:dhi-dss7016dr-s2_firmware:8.0.2:*:*:*:*:*:*:*
cpe:2.3:o:dahuasecurity:dhi-dss7016dr-s2_firmware:8.0.4:*:*:*:*:*:*:*
cpe:2.3:o:dahuasecurity:dhi-dss7016dr-s2_firmware:8.1:*:*:*:*:*:*:*
cpe:2.3:h:dahuasecurity:dhi-dss7016dr-s2:-:*:*:*:*:*:*:*
Конфигурация 3

Одновременно

Одно из

cpe:2.3:o:dahuasecurity:dhi-dss4004-s2_firmware:1.001.0000001.2:*:*:*:*:*:*:*
cpe:2.3:o:dahuasecurity:dhi-dss4004-s2_firmware:8.0.2:*:*:*:*:*:*:*
cpe:2.3:o:dahuasecurity:dhi-dss4004-s2_firmware:8.0.4:*:*:*:*:*:*:*
cpe:2.3:o:dahuasecurity:dhi-dss4004-s2_firmware:8.1:*:*:*:*:*:*:*
cpe:2.3:h:dahuasecurity:dhi-dss4004-s2:-:*:*:*:*:*:*:*
Конфигурация 4

Одновременно

Одно из

cpe:2.3:a:dahuasecurity:dss_express:7.002.1760000.2:*:*:*:*:*:*:*
cpe:2.3:a:dahuasecurity:dss_express:8.0.2:*:*:*:*:*:*:*
cpe:2.3:a:dahuasecurity:dss_express:8.0.4:*:*:*:*:*:*:*
cpe:2.3:a:dahuasecurity:dss_express:8.1:*:*:*:*:*:*:*
cpe:2.3:a:dahuasecurity:dss_express:8.1.1:*:*:*:*:*:*:*
cpe:2.3:a:dahuasecurity:dss_professional:7.002.1760000.2:*:*:*:*:*:*:*
cpe:2.3:a:dahuasecurity:dss_professional:8.0.2:*:*:*:*:*:*:*
cpe:2.3:a:dahuasecurity:dss_professional:8.0.4:*:*:*:*:*:*:*
cpe:2.3:a:dahuasecurity:dss_professional:8.1:*:*:*:*:*:*:*
cpe:2.3:a:dahuasecurity:dss_professional:8.1.1:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

EPSS

Процентиль: 44%
0.00213
Низкий

5.9 Medium

CVSS3

Дефекты

NVD-CWE-noinfo
CWE-770

Связанные уязвимости

CVSS3: 5.9
github
около 3 лет назад

Some Dahua software products have a vulnerability of unauthenticated un-throttled ICMP requests on remote DSS Server. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could exploit the victim server to launch ICMP request attack to the designated target host.

EPSS

Процентиль: 44%
0.00213
Низкий

5.9 Medium

CVSS3

Дефекты

NVD-CWE-noinfo
CWE-770