CVE-2022-30564

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
09/02/2023
Last modified:
25/03/2025

Description

Some Dahua embedded products have a vulnerability of unauthorized modification of the device timestamp. By sending a specially crafted packet to the vulnerable interface, an attacker can modify the device system time.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:dahuasecurity:ipc-hf71242f-z-x_firmware:*:*:*:*:*:*:*:* 2.800.0000000.4.r.210708 (excluding)
cpe:2.3:h:dahuasecurity:ipc-hf71242f-z-x:-:*:*:*:*:*:*:*
cpe:2.3:o:dahuasecurity:ipc-hf7442f-z-x_firmware:*:*:*:*:*:*:*:* 2.800.0000000.4.r.210708 (excluding)
cpe:2.3:h:dahuasecurity:ipc-hf7442f-z-x:-:*:*:*:*:*:*:*
cpe:2.3:o:dahuasecurity:ipc-hf7842f-z-x_firmware:*:*:*:*:*:*:*:* 2.800.0000000.4.r.210708 (excluding)
cpe:2.3:h:dahuasecurity:ipc-hf7842f-z-x:-:*:*:*:*:*:*:*
cpe:2.3:o:dahuasecurity:ipc-hf5241f-ze_firmware:*:*:*:*:*:*:*:* 2.840.0000000.18.r.220629 (excluding)
cpe:2.3:h:dahuasecurity:ipc-hf5241f-ze:-:*:*:*:*:*:*:*
cpe:2.3:o:dahuasecurity:ipc-hf5442f-ze_firmware:*:*:*:*:*:*:*:* 2.840.0000000.18.r.220629 (excluding)
cpe:2.3:h:dahuasecurity:ipc-hf5442f-ze:-:*:*:*:*:*:*:*
cpe:2.3:o:dahuasecurity:ipc-hf5541f-ze_firmware:*:*:*:*:*:*:*:* 2.840.0000000.18.r.220629 (excluding)
cpe:2.3:h:dahuasecurity:ipc-hf5541f-ze:-:*:*:*:*:*:*:*
cpe:2.3:o:dahuasecurity:ipc-hf5842f-ze_firmware:*:*:*:*:*:*:*:* 2.840.0000000.18.r.220629 (excluding)
cpe:2.3:h:dahuasecurity:ipc-hf5842f-ze:-:*:*:*:*:*:*:*
cpe:2.3:o:dahuasecurity:sd5a225gb-hnr_firmware:*:*:*:*:*:*:*:* 2.812.0000032.2.r.220804 (excluding)