CVE-2020-9502
Severity CVSS v4.0:
Pending analysis
Type:
CWE-330
Use of Insufficiently Random Value
Publication date:
13/05/2020
Last modified:
18/05/2020
Description
Some Dahua products with Build time before December 2019 have Session ID predictable vulnerabilities. During normal user access, an attacker can use the predicted Session ID to construct a data packet to attack the device.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:dahuasecurity:sd6al_firmware:*:*:*:*:*:*:*:* | 2019-12 (excluding) | |
| cpe:2.3:h:dahuasecurity:sd6al:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dahuasecurity:sd5a_firmware:*:*:*:*:*:*:*:* | 2019-12 (excluding) | |
| cpe:2.3:h:dahuasecurity:sd5a:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dahuasecurity:sd1a_firmware:*:*:*:*:*:*:*:* | 2019-12 (excluding) | |
| cpe:2.3:h:dahuasecurity:sd1a:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dahuasecurity:ptz1a_firmware:*:*:*:*:*:*:*:* | 2019-12 (excluding) | |
| cpe:2.3:h:dahuasecurity:ptz1a:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dahuasecurity:sd50_firmware:*:*:*:*:*:*:*:* | 2019-12 (excluding) | |
| cpe:2.3:h:dahuasecurity:sd50:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dahuasecurity:sd52c_firmware:*:*:*:*:*:*:*:* | 2019-12 (excluding) | |
| cpe:2.3:h:dahuasecurity:sd52c:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dahuasecurity:ipc-hx5842h_firmware:*:*:*:*:*:*:*:* | 2019-12 (excluding) | |
| cpe:2.3:h:dahuasecurity:ipc-hx5842h:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dahuasecurity:ipc-hx7842h_firmware:*:*:*:*:*:*:*:* | 2019-12 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



