CVE-2020-9499

Severity CVSS v4.0:
Pending analysis
Type:
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
09/04/2020
Last modified:
19/04/2021

Description

Some Dahua products have buffer overflow vulnerabilities. After the successful login of the legal account, the attacker sends a specific DDNS test command, which may cause the device to go down.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:dahuasecurity:sd6al_firmware:*:*:*:*:*:*:*:* 2019-12 (excluding)
cpe:2.3:h:dahuasecurity:sd6al:-:*:*:*:*:*:*:*
cpe:2.3:o:dahuasecurity:sd5a_firmware:*:*:*:*:*:*:*:* 2019-12 (excluding)
cpe:2.3:h:dahuasecurity:sd5a:-:*:*:*:*:*:*:*
cpe:2.3:o:dahuasecurity:sd1a_firmware:*:*:*:*:*:*:*:* 2019-12 (excluding)
cpe:2.3:h:dahuasecurity:sd1a:-:*:*:*:*:*:*:*
cpe:2.3:o:dahuasecurity:ptz1a_firmware:*:*:*:*:*:*:*:* 2019-12 (excluding)
cpe:2.3:h:dahuasecurity:ptz1a:-:*:*:*:*:*:*:*
cpe:2.3:o:dahuasecurity:sd50_firmware:*:*:*:*:*:*:*:* 2019-12 (excluding)
cpe:2.3:h:dahuasecurity:sd50:-:*:*:*:*:*:*:*
cpe:2.3:o:dahuasecurity:sd52c_firmware:*:*:*:*:*:*:*:* 2019-12 (excluding)
cpe:2.3:h:dahuasecurity:sd52c:-:*:*:*:*:*:*:*
cpe:2.3:o:dahuasecurity:ipc-hx5842h_firmware:*:*:*:*:*:*:*:* 2019-12 (excluding)
cpe:2.3:h:dahuasecurity:ipc-hx5842h:-:*:*:*:*:*:*:*
cpe:2.3:o:dahuasecurity:ipc-hx7842h_firmware:*:*:*:*:*:*:*:* 2019-12 (excluding)


References to Advisories, Solutions, and Tools