HIGH · 7.5

CVE-2019-9678

Some Dahua products have the problem of denial of service during the login process. An attacker can cause a device crashed by constructing a malicious packet. Affected products include: IPC-HDW1X2X,IP...

Vulnerability Description

Some Dahua products have the problem of denial of service during the login process. An attacker can cause a device crashed by constructing a malicious packet. Affected products include: IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X,IPC-HFW2X2X,IPC-HDW4X2X,IPC-HFW4X2X,IPC-HDBW4X2X,IPC-HDW5X2X,IPC-HFW5X2X for versions which Build time is before August 18, 2019.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
DahuasecurityIpc-Hdw1X2X Firmware< 2019-08-18
DahuasecurityIpc-Hdw1X2X-
DahuasecurityIpc-Hfw1X2X Firmware< 2019-08-18
DahuasecurityIpc-Hfw1X2X-
DahuasecurityIpc-Hdw2X2X Firmware< 2019-08-18
DahuasecurityIpc-Hdw2X2X-
DahuasecurityIpc-Hfw2X2X Firmware< 2019-08-18
DahuasecurityIpc-Hfw2X2X-
DahuasecurityIpc-Hdw4X2X Firmware< 2019-08-18
DahuasecurityIpc-Hdw4X2X-
DahuasecurityIpc-Hfw4X2X Firmware< 2019-08-18
DahuasecurityIpc-Hfw4X2X-
DahuasecurityIpc-Hdbw4X2X Firmware< 2019-08-18
DahuasecurityIpc-Hdbw4X2X-
DahuasecurityIpc-Hdw5X2X Firmware< 2019-08-18
DahuasecurityIpc-Hdw5X2X-
DahuasecurityIpc-Hfw5X2X Firmware< 2019-08-18
DahuasecurityIpc-Hfw5X2X-

References

FAQ

What is CVE-2019-9678?

CVE-2019-9678 is a vulnerability with a CVSS score of 7.5 (HIGH). Some Dahua products have the problem of denial of service during the login process. An attacker can cause a device crashed by constructing a malicious packet. Affected products include: IPC-HDW1X2X,IP...

How severe is CVE-2019-9678?

CVE-2019-9678 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-9678?

Check the references section above for vendor advisories and patch information. Affected products include: Dahuasecurity Ipc-Hdw1X2X Firmware, Dahuasecurity Ipc-Hdw1X2X, Dahuasecurity Ipc-Hfw1X2X Firmware, Dahuasecurity Ipc-Hfw1X2X, Dahuasecurity Ipc-Hdw2X2X Firmware.