MEDIUM · 5.3

CVE-2019-9680

Some Dahua products have information leakage issues. Attackers can obtain the IP address and device model information of the device by constructing malicious data packets. Affected products include: I...

Vulnerability Description

Some Dahua products have information leakage issues. Attackers can obtain the IP address and device model information of the device by constructing malicious data packets. Affected products include: IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X,IPC-HFW2X2X,IPC-HDW4X2X,IPC-HFW4X2X,IPC-HDBW4X2X,IPC-HDW5X2X,IPC-HFW5X2X for versions which Build time is before August 18, 2019.

CVSS Score

5.3

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
DahuasecurityIpc-Hdw1X2X Firmware< 2019-08-18
DahuasecurityIpc-Hdw1X2X-
DahuasecurityIpc-Hfw1X2X Firmware< 2019-08-18
DahuasecurityIpc-Hfw1X2X-
DahuasecurityIpc-Hdw2X2X Firmware< 2019-08-18
DahuasecurityIpc-Hdw2X2X-
DahuasecurityIpc-Hfw2X2X Firmware< 2019-08-18
DahuasecurityIpc-Hfw2X2X-
DahuasecurityIpc-Hdw4X2X Firmware< 2019-08-18
DahuasecurityIpc-Hdw4X2X-
DahuasecurityIpc-Hfw4X2X Firmware< 2019-08-18
DahuasecurityIpc-Hfw4X2X-
DahuasecurityIpc-Hdbw4X2X Firmware< 2019-08-18
DahuasecurityIpc-Hdbw4X2X-
DahuasecurityIpc-Hdw5X2X Firmware< 2019-08-18
DahuasecurityIpc-Hdw5X2X-
DahuasecurityIpc-Hfw5X2X Firmware< 2019-08-18
DahuasecurityIpc-Hfw5X2X-

References

FAQ

What is CVE-2019-9680?

CVE-2019-9680 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Some Dahua products have information leakage issues. Attackers can obtain the IP address and device model information of the device by constructing malicious data packets. Affected products include: I...

How severe is CVE-2019-9680?

CVE-2019-9680 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-9680?

Check the references section above for vendor advisories and patch information. Affected products include: Dahuasecurity Ipc-Hdw1X2X Firmware, Dahuasecurity Ipc-Hdw1X2X, Dahuasecurity Ipc-Hfw1X2X Firmware, Dahuasecurity Ipc-Hfw1X2X, Dahuasecurity Ipc-Hdw2X2X Firmware.