CVE-2024-39945
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
31/07/2024
Last modified:
27/03/2025
Description
A vulnerability has been found in Dahua products. After<br />
obtaining the administrator&#39;s username and password, the attacker can send a<br />
carefully crafted data packet to the interface with vulnerabilities, causing<br />
the device to crash.
Impact
Base Score 3.x
4.90
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:dahuasecurity:nvr4104-4ks2\/l_firmware:*:*:*:*:*:*:*:* | 4.003.0000000.1.r.240515 (excluding) | |
| cpe:2.3:h:dahuasecurity:nvr4104-4ks2\/l:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dahuasecurity:nvr4108-4ks2\/l_firmware:4.003.0000000.1.r.240515:*:*:*:*:*:*:* | ||
| cpe:2.3:h:dahuasecurity:nvr4108-4ks2\/l:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dahuasecurity:nvr4116-4ks2\/l_firmware:*:*:*:*:*:*:*:* | 4.003.0000000.1.r.240515 (excluding) | |
| cpe:2.3:h:dahuasecurity:nvr4116-4ks2\/l:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dahuasecurity:nvr4104-p-4ks2\/l_firmware:*:*:*:*:*:*:*:* | 4.003.0000000.1.r.240515 (excluding) | |
| cpe:2.3:h:dahuasecurity:nvr4104-p-4ks2\/l:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dahuasecurity:nvr4108-p-4ks2\/l_firmware:*:*:*:*:*:*:*:* | 4.003.0000000.1.r.240515 (excluding) | |
| cpe:2.3:h:dahuasecurity:nvr4108-p-4ks2\/l:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dahuasecurity:nvr4108-8p-4ks2\/l_firmware:*:*:*:*:*:*:*:* | 4.003.0000000.1.r.240515 (excluding) | |
| cpe:2.3:h:dahuasecurity:nvr4108-8p-4ks2\/l:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dahuasecurity:nvr4116-8p-4ks2\/l_firmware:*:*:*:*:*:*:*:* | 4.003.0000000.1.r.240515 (excluding) | |
| cpe:2.3:h:dahuasecurity:nvr4116-8p-4ks2\/l:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dahuasecurity:nvr4104hs-4ks2\/l_firmware:*:*:*:*:*:*:*:* | 4.003.0000000.1.r.240515 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



