HIGH · 8.8

CVE-2019-9679

Some of Dahua's Debug functions do not have permission separation. Low-privileged users can use the Debug function after logging in. Affected products include: IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X,IPC-...

Vulnerability Description

Some of Dahua's Debug functions do not have permission separation. Low-privileged users can use the Debug function after logging in. Affected products include: IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X,IPC-HFW2X2X,IPC-HDW4X2X,IPC-HFW4X2X,IPC-HDBW4X2X,IPC-HDW5X2X,IPC-HFW5X2X for versions which Build time is before August 18,2019.

CVSS Score

8.8

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
DahuasecurityIpc-Hdw1X2X Firmware< 2019-08-18
DahuasecurityIpc-Hdw1X2X-
DahuasecurityIpc-Hfw1X2X Firmware< 2019-08-18
DahuasecurityIpc-Hfw1X2X-
DahuasecurityIpc-Hdw2X2X Firmware< 2019-08-18
DahuasecurityIpc-Hdw2X2X-
DahuasecurityIpc-Hfw2X2X Firmware< 2019-08-18
DahuasecurityIpc-Hfw2X2X-
DahuasecurityIpc-Hdw4X2X Firmware< 2019-08-18
DahuasecurityIpc-Hdw4X2X-
DahuasecurityIpc-Hfw4X2X Firmware< 2019-08-18
DahuasecurityIpc-Hfw4X2X-
DahuasecurityIpc-Hdbw4X2X Firmware< 2019-08-18
DahuasecurityIpc-Hdbw4X2X-
DahuasecurityIpc-Hdw5X2X Firmware< 2019-08-18
DahuasecurityIpc-Hdw5X2X-
DahuasecurityIpc-Hfw5X2X Firmware< 2019-08-18
DahuasecurityIpc-Hfw5X2X-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-9679?

CVE-2019-9679 is a vulnerability with a CVSS score of 8.8 (HIGH). Some of Dahua's Debug functions do not have permission separation. Low-privileged users can use the Debug function after logging in. Affected products include: IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X,IPC-...

How severe is CVE-2019-9679?

CVE-2019-9679 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-9679?

Check the references section above for vendor advisories and patch information. Affected products include: Dahuasecurity Ipc-Hdw1X2X Firmware, Dahuasecurity Ipc-Hdw1X2X, Dahuasecurity Ipc-Hfw1X2X Firmware, Dahuasecurity Ipc-Hfw1X2X, Dahuasecurity Ipc-Hdw2X2X Firmware.