Some Dahua products have access control vulnerability in the password reset process. Attackers can exploit this vulnerability through specific deployments to reset device passwords.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
https://www.dahuasecurity.com/support/cybersecurity/details/957 | not applicable |
https://www.dahuasecurity.com/support/cybersecurity/details/987 | vendor advisory |
https://support.dahuatech.com/networkSecurity/securityDetails?id=95 | vendor advisory |