Description
Online upgrade information in some firmware packages of Dahua products is not encrypted. Attackers can obtain this information by analyzing firmware packages by specific means. Affected products include: IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X,IPC-HFW2X2X,IPC-HDW4X2X,IPC-HFW4X2X,IPC-HDBW4X2X,IPC-HDW5X2X,IPC-HFW5X2X for versions which Build time is before August 18,2019.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-19047 | Online upgrade information in some firmware packages of Dahua products is not encrypted. Attackers can obtain this information by analyzing firmware packages by specific means. Affected products include: IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X,IPC-HFW2X2X,IPC-HDW4X2X,IPC-HFW4X2X,IPC-HDBW4X2X,IPC-HDW5X2X,IPC-HFW5X2X for versions which Build time is before August 18,2019. |
References
History
No history.
Subscriptions
Dahuasecurity
Subscribe
Ipc-hdbw4x2x
Subscribe
Ipc-hdbw4x2x Firmware
Subscribe
Ipc-hdw1x2x
Subscribe
Ipc-hdw1x2x Firmware
Subscribe
Ipc-hdw2x2x
Subscribe
Ipc-hdw2x2x Firmware
Subscribe
Ipc-hdw4x2x
Subscribe
Ipc-hdw4x2x Firmware
Subscribe
Ipc-hdw5x2x
Subscribe
Ipc-hdw5x2x Firmware
Subscribe
Ipc-hfw1x2x
Subscribe
Ipc-hfw1x2x Firmware
Subscribe
Ipc-hfw2x2x
Subscribe
Ipc-hfw2x2x Firmware
Subscribe
Ipc-hfw4x2x
Subscribe
Ipc-hfw4x2x Firmware
Subscribe
Ipc-hfw5x2x
Subscribe
Ipc-hfw5x2x Firmware
Subscribe
Status: PUBLISHED
Assigner: dahua
Published:
Updated: 2024-08-04T21:54:45.133Z
Reserved: 2019-03-11T00:00:00.000Z
Link: CVE-2019-9681
No data.
Status : Modified
Published: 2019-09-17T17:15:12.707
Modified: 2024-11-21T04:52:06.270
Link: CVE-2019-9681
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD