HIGH · 7.2

CVE-2020-9499

Some Dahua products have buffer overflow vulnerabilities. After the successful login of the legal account, the attacker sends a specific DDNS test command, which may cause the device to go down.

Vulnerability Description

Some Dahua products have buffer overflow vulnerabilities. After the successful login of the legal account, the attacker sends a specific DDNS test command, which may cause the device to go down.

CVSS Score

7.2

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
DahuasecuritySd6Al Firmware< 2019-12
DahuasecuritySd6Al-
DahuasecuritySd5A Firmware< 2019-12
DahuasecuritySd5A-
DahuasecuritySd1A Firmware< 2019-12
DahuasecuritySd1A-
DahuasecurityPtz1A Firmware< 2019-12
DahuasecurityPtz1A-
DahuasecuritySd50 Firmware< 2019-12
DahuasecuritySd50-
DahuasecuritySd52C Firmware< 2019-12
DahuasecuritySd52C-
DahuasecurityIpc-Hx5842H Firmware< 2019-12
DahuasecurityIpc-Hx5842H-
DahuasecurityIpc-Hx7842H Firmware< 2019-12
DahuasecurityIpc-Hx7842H-
DahuasecurityIpc-Hx2Xxx Firmware< 2019-12
DahuasecurityIpc-Hx2Xxx-
DahuasecurityIpc-Hxxx5X4X Firmware< 2019-12
DahuasecurityIpc-Hxxx5X4X-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-9499?

CVE-2020-9499 is a vulnerability with a CVSS score of 7.2 (HIGH). Some Dahua products have buffer overflow vulnerabilities. After the successful login of the legal account, the attacker sends a specific DDNS test command, which may cause the device to go down.

How severe is CVE-2020-9499?

CVE-2020-9499 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-9499?

Check the references section above for vendor advisories and patch information. Affected products include: Dahuasecurity Sd6Al Firmware, Dahuasecurity Sd6Al, Dahuasecurity Sd5A Firmware, Dahuasecurity Sd5A, Dahuasecurity Sd1A Firmware.