CVE-2022-45434
27.12.2022, 18:15
Some Dahua software products have a vulnerability of unauthenticated un-throttled ICMP requests on remote DSS Server. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could exploit the victim server to launch ICMP request attack to the designated target host.Enginsight
Vendor | Product | Version |
---|---|---|
dahuasecurity | dhi-dss7016d-s2_firmware | 1.001.0000001.2 |
dahuasecurity | dhi-dss7016d-s2_firmware | 8.0.2 |
dahuasecurity | dhi-dss7016d-s2_firmware | 8.0.4 |
dahuasecurity | dhi-dss7016d-s2_firmware | 8.1 |
dahuasecurity | dhi-dss7016dr-s2_firmware | 1.001.0000001.2 |
dahuasecurity | dhi-dss7016dr-s2_firmware | 8.0.2 |
dahuasecurity | dhi-dss7016dr-s2_firmware | 8.0.4 |
dahuasecurity | dhi-dss7016dr-s2_firmware | 8.1 |
dahuasecurity | dhi-dss4004-s2_firmware | 1.001.0000001.2 |
dahuasecurity | dhi-dss4004-s2_firmware | 8.0.2 |
dahuasecurity | dhi-dss4004-s2_firmware | 8.0.4 |
dahuasecurity | dhi-dss4004-s2_firmware | 8.1 |
dahuasecurity | dss_express | 7.002.1760000.2 |
dahuasecurity | dss_express | 8.0.2 |
dahuasecurity | dss_express | 8.0.4 |
dahuasecurity | dss_express | 8.1 |
dahuasecurity | dss_express | 8.1.1 |
dahuasecurity | dss_professional | 7.002.1760000.2 |
dahuasecurity | dss_professional | 8.0.2 |
dahuasecurity | dss_professional | 8.0.4 |
dahuasecurity | dss_professional | 8.1 |
dahuasecurity | dss_professional | 8.1.1 |
𝑥
= Vulnerable software versions