CVE-2020-9499

Some Dahua products have buffer overflow vulnerabilities. After the successful login of the legal account, the attacker sends a specific DDNS test command, which may cause the device to go down.
Classic Buffer Overflow
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
dahuaCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 57%
VendorProductVersion
dahuasecuritysd6al_firmware
𝑥
< 2019-12
dahuasecuritysd5a_firmware
𝑥
< 2019-12
dahuasecuritysd1a_firmware
𝑥
< 2019-12
dahuasecurityptz1a_firmware
𝑥
< 2019-12
dahuasecuritysd50_firmware
𝑥
< 2019-12
dahuasecuritysd52c_firmware
𝑥
< 2019-12
dahuasecurityipc-hx5842h_firmware
𝑥
< 2019-12
dahuasecurityipc-hx7842h_firmware
𝑥
< 2019-12
dahuasecurityipc-hx2xxx_firmware
𝑥
< 2019-12
dahuasecurityipc-hxxx5x4x_firmware
𝑥
< 2019-12
dahuasecurityn42b1p_firmware
𝑥
< 2019-12
dahuasecurityn42b2p_firmware
𝑥
< 2019-12
dahuasecurityn42b3p_firmware
𝑥
< 2019-12
dahuasecurityn52a4p_firmware
𝑥
< 2019-12
dahuasecurityn54a4p_firmware
𝑥
< 2019-12
dahuasecurityn52b2p_firmware
𝑥
< 2019-12
dahuasecurityn52b5p_firmware
𝑥
< 2019-12
dahuasecurityn52b3p_firmware
𝑥
< 2019-12
dahuasecurityn54b2p_firmware
𝑥
< 2019-12
𝑥
= Vulnerable software versions