CVE-2022-45429

EUVD-2022-48301
Some Dahua software products have a vulnerability of server-side request forgery (SSRF). An Attacker can access internal resources by concatenating links (URL) that conform to specific rules.
SSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA-ADPADP
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 50%
Affected Products (NVD)
VendorProductVersion
dahuasecuritydss_express
7.002.1760000.2
dahuasecuritydss_express
8.0.2
dahuasecuritydss_express
8.0.4
dahuasecuritydss_express
8.1
dahuasecuritydss_express
8.1.1
dahuasecuritydss_professional
7.002.1760000.2
dahuasecuritydss_professional
8.0.2
dahuasecuritydss_professional
8.0.4
dahuasecuritydss_professional
8.1
dahuasecuritydss_professional
8.1.1
dahuasecuritydhi-dss7016d-s2_firmware
1.001.0000001.2
dahuasecuritydhi-dss7016d-s2_firmware
8.0.2
dahuasecuritydhi-dss7016d-s2_firmware
8.0.4
dahuasecuritydhi-dss7016d-s2_firmware
8.1
dahuasecuritydhi-dss7016dr-s2_firmware
1.001.0000001.2
dahuasecuritydhi-dss7016dr-s2_firmware
8.0.2
dahuasecuritydhi-dss7016dr-s2_firmware
8.0.4
dahuasecuritydhi-dss7016dr-s2_firmware
8.1
dahuasecuritydhi-dss4004-s2_firmware
1.001.0000001.2
dahuasecuritydhi-dss4004-s2_firmware
8.0.2
dahuasecuritydhi-dss4004-s2_firmware
8.0.4
dahuasecuritydhi-dss4004-s2_firmware
8.1
𝑥
= Vulnerable software versions