Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2022-45428

Quick assessment

Affected
n/a DSS Professional, DSS Express, DHI-DSS7016D-S2/DHI-DSS7016DR-S2, DHI-DSS4004-S2
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Dahua software products是中国大华(Dahua)公司的一系列应用程序。 若干Dahua软件产品存在安全漏洞,该漏洞源于其敏感信息被泄露允许攻击者在获得管理员权限后通过发送特定的精心制作的报文可以获取debugging信息。

AI Predicted 5.3 Difficulty: Easy EPSS 0.68% · P49

Possible ATT&CK Techniques 1 AI

T1530 · Data from Cloud Storage
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2022-45428

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Some Dahua software products have a vulnerability of sensitive information leakage. After obtaining the permissions of administrators, by sending a specific crafted packet to the vulnerable interface, an attacker can obtain the debugging information.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Dahua software products 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Dahua software products是中国大华(Dahua)公司的一系列应用程序。 若干Dahua软件产品存在安全漏洞,该漏洞源于其敏感信息被泄露允许攻击者在获得管理员权限后通过发送特定的精心制作的报文可以获取debugging信息。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- DSS Professional, DSS Express, DHI-DSS7016D-S2/DHI-DSS7016DR-S2, DHI-DSS4004-S2 V8.0.2, V8.0.4, V8.1 -

II. Public POCs for CVE-2022-45428

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2022-45428

登录查看更多情报信息。

Other References for CVE-2022-45428 (1)

Same Patch Batch · n/a · 2022-12-27 · 26 CVEs total

CVE-2021-4290 5.5 MEDIUM DHBW Fallstudie Login passport.js sql injection
CVE-2022-4748 5.5 MEDIUM FlatPress File Delete panel.mediamanager.file.php doItemActions path traversal
CVE-2022-4772 4.5 MEDIUM Widoco WidocoUtils.java unZipIt path traversal
CVE-2022-4766 4.3 MEDIUM dolibarr_project_timesheet Form cross-site request forgery
CVE-2020-36633 4.3 MEDIUM moodle-block_sitenews block_sitenews.php get_content cross-site request forgery
CVE-2019-25091 3.7 LOW nsupdate.info CSRF Cookie base.py cookie httponly flag
CVE-2022-4755 3.5 LOW FlatPress Media Manager Plugin panel.mediamanager.file.php main cross site scripting
CVE-2015-10005 3.5 LOW markdown-it html_re.js redos
CVE-2018-25049 3.0 LOW email-existence index.js redos
CVE-2022-4773 2.5 LOW cloudsync LocalFilesystemConnector.java getItem path traversal
CVE-2022-47968 Heimdal 跨站脚本漏洞
CVE-2022-46442 DedeCMS SQL注入漏洞
CVE-2022-45963 H3C Firewall 安全漏洞
CVE-2022-45778 Hillstone Networks Firewall 安全漏洞
CVE-2022-45434 Dahua software products 授权问题漏洞
CVE-2022-45433 Dahua software products 授权问题漏洞
CVE-2022-45432 Dahua software products 授权问题漏洞
CVE-2022-45431 Dahua software products 授权问题漏洞
CVE-2022-45430 Dahua software products 授权问题漏洞
CVE-2022-45429 Dahua software products 代码问题漏洞

Showing top 20 of 26 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2022-45428

No comments yet


Leave a comment