PT-2022-6097 · Dahua · Dhi-Dss7016Dr-S2+4
Published
2022-12-27
·
Updated
2023-01-05
·
CVE-2022-45427
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:S/C:N/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Dahua software products (affected versions not specified)
DSS Professional (affected versions not specified)
DSS Express (affected versions not specified)
DHI-DSS4004-S2 (affected versions not specified)
DHI-DSS7016D-S2 (affected versions not specified)
DHI-DSS7016DR-S2 (affected versions not specified)
Description
The issue is related to an unrestricted upload of file vulnerability. After obtaining administrator permissions, an attacker can upload arbitrary files by sending a crafted packet to the vulnerable interface. This can be exploited remotely.
Recommendations
For Dahua software products, consider restricting access to the vulnerable interface until a patch is available.
For DSS Professional, DSS Express, DHI-DSS4004-S2, DHI-DSS7016D-S2, and DHI-DSS7016DR-S2, restrict the ability to upload files to authorized personnel only.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dhi-Dss4004-S2
Dhi-Dss7016Dr-S2
Dss Express
Dss Professional
Dahua