Improper Access Control Vulnerability in Dahua Security Products
CVE-2019-9679
8.8HIGH
What is CVE-2019-9679?
Dahua Security products possess an access control vulnerability due to insufficient permissions on certain Debug functions, allowing low-privileged users to execute these functions after authentication. This exposure can lead to unauthorized access and potential manipulation of device configuration, affecting the integrity and security of the deployed surveillance systems. Users of the impacted product models built before August 18, 2019, should assess their installation and ensure appropriate security measures are implemented.
Affected Version(s)
IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X,IPC-HFW2X2X,IPC-HDW4X2X,IPC-HFW4X2X,IPC-HDBW4X2X,IPC-HDW5X2X,IPC-HFW5X2X Versions which Build time before August 18 2019
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved