Information Disclosure Vulnerability in Dahua Web P2P Control
CVE-2020-9501

5.5MEDIUM

What is CVE-2020-9501?

The Dahua Web P2P Control vulnerability allows attackers to obtain sensitive Cloud Key information through specific methods. This Cloud Key is crucial for authenticating connections between client tools and the Dahua platform. If compromised, an attacker could leverage the leaked Cloud Key to impersonate legitimate clients, potentially leading to unauthorized access and increased consumption of server resources. Affected versions include those built before April 2020. Ensuring updates are applied is essential for protecting against this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Web P2P control,P2P plartform server,client tools Versions which Build time before April,2020

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.