CVE-2020-9502

Some Dahua products with Build time before December 2019 have Session ID predictable vulnerabilities. During normal user access, an attacker can use the predicted Session ID to construct a data packet to attack the device.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
dahuaCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 65%
VendorProductVersion
dahuasecuritysd6al_firmware
𝑥
< 2019-12
dahuasecuritysd5a_firmware
𝑥
< 2019-12
dahuasecuritysd1a_firmware
𝑥
< 2019-12
dahuasecurityptz1a_firmware
𝑥
< 2019-12
dahuasecuritysd50_firmware
𝑥
< 2019-12
dahuasecuritysd52c_firmware
𝑥
< 2019-12
dahuasecurityipc-hx5842h_firmware
𝑥
< 2019-12
dahuasecurityipc-hx7842h_firmware
𝑥
< 2019-12
dahuasecurityipc-hx2xxx_firmware
𝑥
< 2019-12
dahuasecurityipc-hxxx5x4x_firmware
𝑥
< 2019-12
dahuasecurityn42b1p_firmware
𝑥
< 2019-12
dahuasecurityn42b2p_firmware
𝑥
< 2019-12
dahuasecurityn42b3p_firmware
𝑥
< 2019-12
dahuasecurityn52a4p_firmware
𝑥
< 2019-12
dahuasecurityn54a4p_firmware
𝑥
< 2019-12
dahuasecurityn52b2p_firmware
𝑥
< 2019-12
dahuasecurityn52b5p_firmware
𝑥
< 2019-12
dahuasecurityn52b3p_firmware
𝑥
< 2019-12
dahuasecurityn54b2p_firmware
𝑥
< 2019-12
dahuasecurityipc-hdbw1320e-w_firmware
𝑥
< 2019-12
𝑥
= Vulnerable software versions