Description
The specific fields of CGI interface of some Dahua products are not strictly verified, an attacker can cause a buffer overflow by constructing malicious packets. Affected products include: IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X,IPC-HFW2X2X,IPC-HDW4X2X,IPC-HFW4X2X,IPC-HDBW4X2X,IPC-HDW5X2X,IPC-HFW5X2X for versions which Build time is before August 18, 2019.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-19043 | The specific fields of CGI interface of some Dahua products are not strictly verified, an attacker can cause a buffer overflow by constructing malicious packets. Affected products include: IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X,IPC-HFW2X2X,IPC-HDW4X2X,IPC-HFW4X2X,IPC-HDBW4X2X,IPC-HDW5X2X,IPC-HFW5X2X for versions which Build time is before August 18, 2019. |
References
History
No history.
Subscriptions
Dahuasecurity
Subscribe
Ipc-hdbw4x2x
Subscribe
Ipc-hdbw4x2x Firmware
Subscribe
Ipc-hdw1x2x
Subscribe
Ipc-hdw1x2x Firmware
Subscribe
Ipc-hdw2x2x
Subscribe
Ipc-hdw2x2x Firmware
Subscribe
Ipc-hdw4x2x
Subscribe
Ipc-hdw4x2x Firmware
Subscribe
Ipc-hdw5x2x
Subscribe
Ipc-hdw5x2x Firmware
Subscribe
Ipc-hfw1x2x
Subscribe
Ipc-hfw1x2x Firmware
Subscribe
Ipc-hfw2x2x
Subscribe
Ipc-hfw2x2x Firmware
Subscribe
Ipc-hfw4x2x
Subscribe
Ipc-hfw4x2x Firmware
Subscribe
Ipc-hfw5x2x
Subscribe
Ipc-hfw5x2x Firmware
Subscribe
Status: PUBLISHED
Assigner: dahua
Published:
Updated: 2024-08-04T21:54:45.468Z
Reserved: 2019-03-11T00:00:00.000Z
Link: CVE-2019-9677
No data.
Status : Modified
Published: 2019-09-18T19:15:10.297
Modified: 2024-11-21T04:52:05.813
Link: CVE-2019-9677
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD