HIGH · 8.1

CVE-2019-9682

Dahua devices with Build time before December 2019 use strong security login mode by default, but in order to be compatible with the normal login of early devices, some devices retain the weak securit...

Vulnerability Description

Dahua devices with Build time before December 2019 use strong security login mode by default, but in order to be compatible with the normal login of early devices, some devices retain the weak security login mode that users can control. If the user uses a weak security login method, an attacker can monitor the device network to intercept network packets to attack the device. So it is recommended that the user disable this login method.

CVSS Score

8.1

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
DahuasecuritySd6Al Firmware< 2019-12
DahuasecuritySd6Al-
DahuasecuritySd5A Firmware< 2019-12
DahuasecuritySd5A-
DahuasecuritySd1A Firmware< 2019-12
DahuasecuritySd1A-
DahuasecurityPtz1A Firmware< 2019-12
DahuasecurityPtz1A-
DahuasecuritySd50 Firmware< 2019-12
DahuasecuritySd50-
DahuasecuritySd52C Firmware< 2019-12
DahuasecuritySd52C-
DahuasecurityIpc-Hx5842H Firmware< 2019-12
DahuasecurityIpc-Hx5842H-
DahuasecurityIpc-Hx7842H Firmware< 2019-12
DahuasecurityIpc-Hx7842H-
DahuasecurityIpc-Hx2Xxx Firmware< 2019-12
DahuasecurityIpc-Hx2Xxx-
DahuasecurityIpc-Hxxx5X4X Firmware< 2019-12
DahuasecurityIpc-Hxxx5X4X-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-9682?

CVE-2019-9682 is a vulnerability with a CVSS score of 8.1 (HIGH). Dahua devices with Build time before December 2019 use strong security login mode by default, but in order to be compatible with the normal login of early devices, some devices retain the weak securit...

How severe is CVE-2019-9682?

CVE-2019-9682 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-9682?

Check the references section above for vendor advisories and patch information. Affected products include: Dahuasecurity Sd6Al Firmware, Dahuasecurity Sd6Al, Dahuasecurity Sd5A Firmware, Dahuasecurity Sd5A, Dahuasecurity Sd1A Firmware.