Information Leakage Vulnerability in Dahua Security Products
CVE-2019-9680
5.3MEDIUM
What is CVE-2019-9680?
Certain Dahua security camera models are susceptible to information leakage vulnerabilities, enabling attackers to retrieve sensitive data such as the device's IP address and model number through the exploitation of malicious data packets. Affected devices include numerous models in the IPC-HDW and IPC-HFW series, specifically those with build dates prior to August 18, 2019. Users are advised to upgrade their devices to the latest versions to mitigate the risk.
Affected Version(s)
IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X,IPC-HFW2X2X,IPC-HDW4X2X,IPC-HFW4X2X,IPC-HDBW4X2X,IPC-HDW5X2X,IPC-HFW5X2X Versions which Build time before August 18 2019
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved