The specific fields of CGI interface of some Dahua products are not strictly verified, an attacker can cause a buffer overflow by constructing malicious packets. Affected products include: IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X,IPC-HFW2X2X,IPC-HDW4X2X,IPC-HFW4X2X,IPC-HDBW4X2X,IPC-HDW5X2X,IPC-HFW5X2X for versions which Build time is before August 18, 2019.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
dahuasecurity ipc-hdw1x2x_firmware |
||
dahuasecurity ipc-hfw1x2x_firmware |
||
dahuasecurity ipc-hdw2x2x_firmware |
||
dahuasecurity ipc-hfw2x2x_firmware |
||
dahuasecurity ipc-hdw4x2x_firmware |
||
dahuasecurity ipc-hfw4x2x_firmware |
||
dahuasecurity ipc-hdbw4x2x_firmware |
||
dahuasecurity ipc-hdw5x2x_firmware |
||
dahuasecurity ipc-hfw5x2x_firmware |