Vulnerability Description
Some Dahua products with Build time before December 2019 have Session ID predictable vulnerabilities. During normal user access, an attacker can use the predicted Session ID to construct a data packet to attack the device.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dahuasecurity | Sd6Al Firmware | < 2019-12 |
| Dahuasecurity | Sd6Al | - |
| Dahuasecurity | Sd5A Firmware | < 2019-12 |
| Dahuasecurity | Sd5A | - |
| Dahuasecurity | Sd1A Firmware | < 2019-12 |
| Dahuasecurity | Sd1A | - |
| Dahuasecurity | Ptz1A Firmware | < 2019-12 |
| Dahuasecurity | Ptz1A | - |
| Dahuasecurity | Sd50 Firmware | < 2019-12 |
| Dahuasecurity | Sd50 | - |
| Dahuasecurity | Sd52C Firmware | < 2019-12 |
| Dahuasecurity | Sd52C | - |
| Dahuasecurity | Ipc-Hx5842H Firmware | < 2019-12 |
| Dahuasecurity | Ipc-Hx5842H | - |
| Dahuasecurity | Ipc-Hx7842H Firmware | < 2019-12 |
| Dahuasecurity | Ipc-Hx7842H | - |
| Dahuasecurity | Ipc-Hx2Xxx Firmware | < 2019-12 |
| Dahuasecurity | Ipc-Hx2Xxx | - |
| Dahuasecurity | Ipc-Hxxx5X4X Firmware | < 2019-12 |
| Dahuasecurity | Ipc-Hxxx5X4X | - |
Related Weaknesses (CWE)
References
- https://www.dahuasecurity.com/support/cybersecurity/details/777Vendor Advisory
- https://www.dahuasecurity.com/support/cybersecurity/details/777Vendor Advisory
FAQ
What is CVE-2020-9502?
CVE-2020-9502 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Some Dahua products with Build time before December 2019 have Session ID predictable vulnerabilities. During normal user access, an attacker can use the predicted Session ID to construct a data packet...
How severe is CVE-2020-9502?
CVE-2020-9502 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-9502?
Check the references section above for vendor advisories and patch information. Affected products include: Dahuasecurity Sd6Al Firmware, Dahuasecurity Sd6Al, Dahuasecurity Sd5A Firmware, Dahuasecurity Sd5A, Dahuasecurity Sd1A Firmware.