PT-2022-3935 · Dahua · Dahua Asi7Xxx+2
Published
2022-06-28
·
Updated
2026-02-06
·
CVE-2022-30563
CVSS v2.0
7.6
High
| Vector | AV:N/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Dahua ASI7XXX versions prior to v1.000.0000009.0.R.220620
Dahua IPC-HDBW2XXX versions prior to v2.820.0000000.48.R.220614
Dahua IPC-HX2XXX versions prior to v2.820.0000000.48.R.220614
Description
The issue is related to the authentication mechanism WS-UsernameToken in ONVIF, which can be exploited by an attacker using a man-in-the-middle attack to sniff request packets and replay the user's login packet, allowing them to log in to the device. This can give the attacker full access to the IP camera. The vulnerability can be used to compromise network cameras by intercepting unencrypted ONVIF interactions and reusing credentials in a new request to the camera, which will be accepted by the device as valid authenticated requests.
Recommendations
For Dahua ASI7XXX versions prior to v1.000.0000009.0.R.220620, update to a version later than v1.000.0000009.0.R.220620 to resolve the issue.
For Dahua IPC-HDBW2XXX versions prior to v2.820.0000000.48.R.220614, update to a version later than v2.820.0000000.48.R.220614 to resolve the issue.
For Dahua IPC-HX2XXX versions prior to v2.820.0000000.48.R.220614, update to a version later than v2.820.0000000.48.R.220614 to resolve the issue.
As a temporary workaround, consider restricting access to ONVIF interactions to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dahua Asi7Xxx
Dahua Ipc-Hdbw2Xxx
Dahua Ipc-Hx2Xxx