Unauthenticated ICMP Request Vulnerability in Dahua Software Products
CVE-2022-45434
5.9MEDIUM
What is CVE-2022-45434?
Dahua software products, particularly the DSS Server, exhibit vulnerability due to unauthenticated and un-throttled ICMP requests. Attackers can exploit this by circumventing firewall access controls to send specially crafted packets, leading to potential ICMP request flooding on the targeted host, which may disrupt network services and compromise the integrity of connected systems.
Affected Version(s)
DSS Professional, DSS Express, DHI-DSS7016D-S2/DHI-DSS7016DR-S2, DHI-DSS4004-S2 V8.0.2, V8.0.4, V8.1
