Security Advisory

CVE-2019-9681

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2019-09-17 16:02:18
Last updated 2024-08-04 21:54:45
Assigner dahua
State PUBLISHED

Description

Online upgrade information in some firmware packages of Dahua products is not encrypted. Attackers can obtain this information by analyzing firmware packages by specific means. Affected products include: IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X,IPC-HFW2X2X,IPC-HDW4X2X,IPC-HFW4X2X,IPC-HDBW4X2X,IPC-HDW5X2X,IPC-HFW5X2X for versions which Build time is before August 18,2019.