CVE-2024-39945

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
31/07/2024
Last modified:
27/03/2025

Description

A vulnerability has been found in Dahua products.  After<br /> obtaining the administrator&amp;#39;s username and password, the attacker can send a<br /> carefully crafted data packet to the interface with vulnerabilities, causing<br /> the device to crash.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:dahuasecurity:nvr4104-4ks2\/l_firmware:*:*:*:*:*:*:*:* 4.003.0000000.1.r.240515 (excluding)
cpe:2.3:h:dahuasecurity:nvr4104-4ks2\/l:-:*:*:*:*:*:*:*
cpe:2.3:o:dahuasecurity:nvr4108-4ks2\/l_firmware:4.003.0000000.1.r.240515:*:*:*:*:*:*:*
cpe:2.3:h:dahuasecurity:nvr4108-4ks2\/l:-:*:*:*:*:*:*:*
cpe:2.3:o:dahuasecurity:nvr4116-4ks2\/l_firmware:*:*:*:*:*:*:*:* 4.003.0000000.1.r.240515 (excluding)
cpe:2.3:h:dahuasecurity:nvr4116-4ks2\/l:-:*:*:*:*:*:*:*
cpe:2.3:o:dahuasecurity:nvr4104-p-4ks2\/l_firmware:*:*:*:*:*:*:*:* 4.003.0000000.1.r.240515 (excluding)
cpe:2.3:h:dahuasecurity:nvr4104-p-4ks2\/l:-:*:*:*:*:*:*:*
cpe:2.3:o:dahuasecurity:nvr4108-p-4ks2\/l_firmware:*:*:*:*:*:*:*:* 4.003.0000000.1.r.240515 (excluding)
cpe:2.3:h:dahuasecurity:nvr4108-p-4ks2\/l:-:*:*:*:*:*:*:*
cpe:2.3:o:dahuasecurity:nvr4108-8p-4ks2\/l_firmware:*:*:*:*:*:*:*:* 4.003.0000000.1.r.240515 (excluding)
cpe:2.3:h:dahuasecurity:nvr4108-8p-4ks2\/l:-:*:*:*:*:*:*:*
cpe:2.3:o:dahuasecurity:nvr4116-8p-4ks2\/l_firmware:*:*:*:*:*:*:*:* 4.003.0000000.1.r.240515 (excluding)
cpe:2.3:h:dahuasecurity:nvr4116-8p-4ks2\/l:-:*:*:*:*:*:*:*
cpe:2.3:o:dahuasecurity:nvr4104hs-4ks2\/l_firmware:*:*:*:*:*:*:*:* 4.003.0000000.1.r.240515 (excluding)


References to Advisories, Solutions, and Tools