CVE Intelligence
Skip to main content

CVE-2019-9679

CVE-2019-9679 Vulnerability Analysis & Exploit Intelligence

Some of Dahua's Debug functions do not have permission separation. Low-privileged users can use the Debug function after logging in. Affected products include: IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X,IPC-HFW2X2X,IPC-HDW4X2X,IPC-HFW4X2X,IPC-HDBW4X2X,IPC-HDW5X2X,IPC-HFW5X2X for versions which Build time is before August 18,2019.

Published Updated Sources: cvelistV5, dahua

Triage

Is it exploited, how likely is exploitation, what does it touch, and how severe do the scoring sources call it.

Exploitation

Unreported

no source claims exploitation

EPSS

1%

chance of exploitation in 30 days

Affects

dahua technology

ipc_hdw1x2x_ipc_hfw1x2x_ipc_hdw2x2x_ipc_hfw2x2x_ipc_hdw4x2x_ipc_hfw4x2x_ipc_hdbw4x2x_ipc_hdw5x2x_ipc_hfw5x2x

CVSS base

Unscored

no source published a base score

Affected scope

The catalog records vendors and products as separate lists, not pairs, so which product belongs to which vendor is not something this page can say.

Vendors (1)

Products (1)

ipc hdw1x2x ipc hfw1x2x ipc hdw2x2x ipc hfw2x2x ipc hdw4x2x ipc hfw4x2x ipc hdbw4x2x ipc hdw5x2x ipc hfw5x2x

References

1 on the record

Elsewhere on this site

Not in any source we poll

Listed rather than left blank: an empty field and an unmeasured one look identical on screen, and only one is a reason to look elsewhere.

  • No confirmed IOCs, IP addresses, domains, file hashes, or malware artifacts supplied.
  • No organization-specific asset inventory, compensating-control status, or patch deployment evidence supplied.
  • No exploit packet captures, log samples, or incident case IDs supplied.