CVE-2019-9679
CVE-2019-9679 Vulnerability Analysis & Exploit Intelligence
Some of Dahua's Debug functions do not have permission separation. Low-privileged users can use the Debug function after logging in. Affected products include: IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X,IPC-HFW2X2X,IPC-HDW4X2X,IPC-HFW4X2X,IPC-HDBW4X2X,IPC-HDW5X2X,IPC-HFW5X2X for versions which Build time is before August 18,2019.
Published Updated Sources: cvelistV5, dahua
Triage
Is it exploited, how likely is exploitation, what does it touch, and how severe do the scoring sources call it.
Exploitation
Unreported
no source claims exploitation
EPSS
1%
chance of exploitation in 30 days
Affects
ipc_hdw1x2x_ipc_hfw1x2x_ipc_hdw2x2x_ipc_hfw2x2x_ipc_hdw4x2x_ipc_hfw4x2x_ipc_hdbw4x2x_ipc_hdw5x2x_ipc_hfw5x2x
CVSS base
Unscored
no source published a base score
Affected scope
The catalog records vendors and products as separate lists, not pairs, so which product belongs to which vendor is not something this page can say.
Vendors (1)
Products (1)
References
1 on the record
- www.dahuasecurity.com/support/cybersecurity/details/637
x_refsource_CONFIRM
Elsewhere on this site
- dahua technologyevery CVE for this vendor
Not in any source we poll
Listed rather than left blank: an empty field and an unmeasured one look identical on screen, and only one is a reason to look elsewhere.
- No confirmed IOCs, IP addresses, domains, file hashes, or malware artifacts supplied.
- No organization-specific asset inventory, compensating-control status, or patch deployment evidence supplied.
- No exploit packet captures, log samples, or incident case IDs supplied.