CVE-2022-30564
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
09/02/2023
Last modified:
25/03/2025
Description
Some Dahua embedded products have a vulnerability of unauthorized modification of the device timestamp. By sending a specially crafted packet to the vulnerable interface, an attacker can modify the device system time.
Impact
Base Score 3.x
5.30
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:dahuasecurity:ipc-hf71242f-z-x_firmware:*:*:*:*:*:*:*:* | 2.800.0000000.4.r.210708 (excluding) | |
| cpe:2.3:h:dahuasecurity:ipc-hf71242f-z-x:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dahuasecurity:ipc-hf7442f-z-x_firmware:*:*:*:*:*:*:*:* | 2.800.0000000.4.r.210708 (excluding) | |
| cpe:2.3:h:dahuasecurity:ipc-hf7442f-z-x:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dahuasecurity:ipc-hf7842f-z-x_firmware:*:*:*:*:*:*:*:* | 2.800.0000000.4.r.210708 (excluding) | |
| cpe:2.3:h:dahuasecurity:ipc-hf7842f-z-x:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dahuasecurity:ipc-hf5241f-ze_firmware:*:*:*:*:*:*:*:* | 2.840.0000000.18.r.220629 (excluding) | |
| cpe:2.3:h:dahuasecurity:ipc-hf5241f-ze:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dahuasecurity:ipc-hf5442f-ze_firmware:*:*:*:*:*:*:*:* | 2.840.0000000.18.r.220629 (excluding) | |
| cpe:2.3:h:dahuasecurity:ipc-hf5442f-ze:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dahuasecurity:ipc-hf5541f-ze_firmware:*:*:*:*:*:*:*:* | 2.840.0000000.18.r.220629 (excluding) | |
| cpe:2.3:h:dahuasecurity:ipc-hf5541f-ze:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dahuasecurity:ipc-hf5842f-ze_firmware:*:*:*:*:*:*:*:* | 2.840.0000000.18.r.220629 (excluding) | |
| cpe:2.3:h:dahuasecurity:ipc-hf5842f-ze:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dahuasecurity:sd5a225gb-hnr_firmware:*:*:*:*:*:*:*:* | 2.812.0000032.2.r.220804 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



