CVE-2020-9502
13.05.2020, 16:15
Some Dahua products with Build time before December 2019 have Session ID predictable vulnerabilities. During normal user access, an attacker can use the predicted Session ID to construct a data packet to attack the device.Enginsight
Vendor | Product | Version |
---|---|---|
dahuasecurity | sd6al_firmware | 𝑥 < 2019-12 |
dahuasecurity | sd5a_firmware | 𝑥 < 2019-12 |
dahuasecurity | sd1a_firmware | 𝑥 < 2019-12 |
dahuasecurity | ptz1a_firmware | 𝑥 < 2019-12 |
dahuasecurity | sd50_firmware | 𝑥 < 2019-12 |
dahuasecurity | sd52c_firmware | 𝑥 < 2019-12 |
dahuasecurity | ipc-hx5842h_firmware | 𝑥 < 2019-12 |
dahuasecurity | ipc-hx7842h_firmware | 𝑥 < 2019-12 |
dahuasecurity | ipc-hx2xxx_firmware | 𝑥 < 2019-12 |
dahuasecurity | ipc-hxxx5x4x_firmware | 𝑥 < 2019-12 |
dahuasecurity | n42b1p_firmware | 𝑥 < 2019-12 |
dahuasecurity | n42b2p_firmware | 𝑥 < 2019-12 |
dahuasecurity | n42b3p_firmware | 𝑥 < 2019-12 |
dahuasecurity | n52a4p_firmware | 𝑥 < 2019-12 |
dahuasecurity | n54a4p_firmware | 𝑥 < 2019-12 |
dahuasecurity | n52b2p_firmware | 𝑥 < 2019-12 |
dahuasecurity | n52b5p_firmware | 𝑥 < 2019-12 |
dahuasecurity | n52b3p_firmware | 𝑥 < 2019-12 |
dahuasecurity | n54b2p_firmware | 𝑥 < 2019-12 |
dahuasecurity | ipc-hdbw1320e-w_firmware | 𝑥 < 2019-12 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration