Dahua products vulnerable to crashing attack through interface
CVE-2024-39949

7.5HIGH

Key Information:

Vendor

Dahua

Status
Vendor
CVE Published:
31 July 2024

What is CVE-2024-39949?

A vulnerability affecting Dahua security devices has been identified, whereby attackers can exploit the device's interface by sending specially crafted data packets. This manipulation can lead to unexpected crashes of the device, potentially compromising system integrity and availability. Enhanced security measures and regular updates are recommended to mitigate risks associated with this vulnerability.

Affected Version(s)

NVR4XXX NVR4XXX Versions which Build time before 2023/12/13

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.