Some Dahua software products have a vulnerability of sensitive information leakage. After obtaining the permissions of administrators, by sending a specific crafted packet to the vulnerable interface, an attacker can obtain the debugging information.
The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.
Link | Tags |
---|---|
https://www.dahuasecurity.com/support/cybersecurity/details/1137 | patch vendor advisory |