Weak Security Login Mode in Dahua Devices Prior to December 2019
CVE-2019-9682

8.1HIGH

What is CVE-2019-9682?

Dahua Security Cameras manufactured before December 2019 may operate with weak login credentials, posing a risk of unauthorized access. Devices initially configured to use a strong security login mode also support a legacy weak login method to maintain compatibility with older models. If users opt for this less secure login method, it may leave devices open to network traffic interception and potential attacks. Users are strongly advised to disable weak login methods to enhance security and protect their devices from threats.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

IPC-HX2XXX Series,IPC-HXXX5X4X Series,IPC-HX5842H,IPC-HX7842H,NVR 5x Series,NVR 4x Series,SD6AL Series,SD5A Series,SD1A Series,PTZ1A Series,SD50/52C Series,IPC-HDBW1320E-W Versions which Build time before December,2019

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.