CVE-2019-9676 Information

Description

Buffer overflow vulnerability found in some Dahua IP Camera devices IPC-HFW1XXXIPC-HDW1XXXIPC-HFW2XXX Build before 2018/11. The vulnerability exits in the function of redirection display for serial port printing information which can not be used by product basic functions. After an attacker logs in locally this vulnerability can be exploited to cause device restart or arbitrary code execution. Dahua has identified the corresponding security problems in the static code auditing process so it has gradually deleted this function which is no longer available in the newer devices and softwares. Dahua has released versions of the affected products to fix the vulnerability.

CVSS Vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Reference

https://www.dahuasecurity.com/support/cybersecurity/details/617

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

7.8

Share on: