CVE-2024-39946
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
31/07/2024
Last modified:
19/08/2024
Description
A vulnerability has been found in Dahua products.After obtaining the administrator's username and password, the attacker can send a carefully crafted data packet to the interface with vulnerabilities, causing device initialization.
Impact
Base Score 3.x
7.20
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:dahuasecurity:nvr4104-4ks2\/l_firmware:*:*:*:*:*:*:*:* | 4.003.0000000.1.r.240515 (excluding) | |
| cpe:2.3:h:dahuasecurity:nvr4104-4ks2\/l:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dahuasecurity:nvr4108-4ks2\/l_firmware:4.003.0000000.1.r.240515:*:*:*:*:*:*:* | ||
| cpe:2.3:h:dahuasecurity:nvr4108-4ks2\/l:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dahuasecurity:nvr4116-4ks2\/l_firmware:*:*:*:*:*:*:*:* | 4.003.0000000.1.r.240515 (excluding) | |
| cpe:2.3:h:dahuasecurity:nvr4116-4ks2\/l:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dahuasecurity:nvr4104-p-4ks2\/l_firmware:*:*:*:*:*:*:*:* | 4.003.0000000.1.r.240515 (excluding) | |
| cpe:2.3:h:dahuasecurity:nvr4104-p-4ks2\/l:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dahuasecurity:nvr4108-p-4ks2\/l_firmware:*:*:*:*:*:*:*:* | 4.003.0000000.1.r.240515 (excluding) | |
| cpe:2.3:h:dahuasecurity:nvr4108-p-4ks2\/l:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dahuasecurity:nvr4108-8p-4ks2\/l_firmware:*:*:*:*:*:*:*:* | 4.003.0000000.1.r.240515 (excluding) | |
| cpe:2.3:h:dahuasecurity:nvr4108-8p-4ks2\/l:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dahuasecurity:nvr4116-8p-4ks2\/l_firmware:*:*:*:*:*:*:*:* | 4.003.0000000.1.r.240515 (excluding) | |
| cpe:2.3:h:dahuasecurity:nvr4116-8p-4ks2\/l:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dahuasecurity:nvr4104hs-4ks2\/l_firmware:*:*:*:*:*:*:*:* | 4.003.0000000.1.r.240515 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



