Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2022-45423

Quick assessment

Affected
n/a DSS Professional, DSS Express, DHI-DSS7016D-S2/DHI-DSS7016DR-S2, DHI-DSS4004-S2
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Dahua software products是中国大华(Dahua)公司的一系列应用程序。 若干Dahua软件产品存在安全漏洞,该漏洞源于其未经认证的MQTT凭证请求允许攻击者通过向易受攻击的接口发送特定的精心制作的数据包来获得加密的MQTT凭据(凭据不能直接利用)。

AI Predicted 5.3 Difficulty: Trivial EPSS 0.57% · P45
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2022-45423

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Some Dahua software products have a vulnerability of unauthenticated request of MQTT credentials. An attacker can obtain encrypted MQTT credentials by sending a specific crafted packet to the vulnerable interface (the credentials cannot be directly exploited).
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Dahua software products 访问控制错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Dahua software products是中国大华(Dahua)公司的一系列应用程序。 若干Dahua软件产品存在安全漏洞,该漏洞源于其未经认证的MQTT凭证请求允许攻击者通过向易受攻击的接口发送特定的精心制作的数据包来获得加密的MQTT凭据(凭据不能直接利用)。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- DSS Professional, DSS Express, DHI-DSS7016D-S2/DHI-DSS7016DR-S2, DHI-DSS4004-S2 V8.0.2, V8.0.4, V8.1 -

II. Public POCs for CVE-2022-45423

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2022-45423

登录查看更多情报信息。

Other References for CVE-2022-45423 (1)

Same Patch Batch · n/a · 2022-12-27 · 26 CVEs total

CVE-2021-4290 5.5 MEDIUM DHBW Fallstudie Login passport.js sql injection
CVE-2022-4748 5.5 MEDIUM FlatPress File Delete panel.mediamanager.file.php doItemActions path traversal
CVE-2022-4772 4.5 MEDIUM Widoco WidocoUtils.java unZipIt path traversal
CVE-2022-4766 4.3 MEDIUM dolibarr_project_timesheet Form cross-site request forgery
CVE-2020-36633 4.3 MEDIUM moodle-block_sitenews block_sitenews.php get_content cross-site request forgery
CVE-2019-25091 3.7 LOW nsupdate.info CSRF Cookie base.py cookie httponly flag
CVE-2022-4755 3.5 LOW FlatPress Media Manager Plugin panel.mediamanager.file.php main cross site scripting
CVE-2015-10005 3.5 LOW markdown-it html_re.js redos
CVE-2018-25049 3.0 LOW email-existence index.js redos
CVE-2022-4773 2.5 LOW cloudsync LocalFilesystemConnector.java getItem path traversal
CVE-2022-47968 Heimdal 跨站脚本漏洞
CVE-2022-46442 DedeCMS SQL注入漏洞
CVE-2022-45963 H3C Firewall 安全漏洞
CVE-2022-45778 Hillstone Networks Firewall 安全漏洞
CVE-2022-45434 Dahua software products 授权问题漏洞
CVE-2022-45433 Dahua software products 授权问题漏洞
CVE-2022-45432 Dahua software products 授权问题漏洞
CVE-2022-45431 Dahua software products 授权问题漏洞
CVE-2022-45430 Dahua software products 授权问题漏洞
CVE-2022-45429 Dahua software products 代码问题漏洞

Showing top 20 of 26 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2022-45423

No comments yet


Leave a comment