Summary
Some Dahua products have Session ID predictable vulnerabilities. During normal user access, an attacker can use the predicted Session ID to construct a data packet to attack the device.
Credit:
The information has been provided by Vendor
The original article can be found at:https://www.dahuasecurity.com/support/cybersecurity/details/777
Details
Some Dahua products with Build time before December 2019 have Session ID predictable vulnerabilities. During normal user access, an attacker can use the predicted Session ID to construct a data packet to attack the device.
Vulnerable Systems:
Dahua products
CVE Information:
Disclosure Timeline:
Published Date:5/13/2020