Overview
- Description
- Dahua IP camera products using firmware versions prior to V2.400.0000.14.R.20170713 include a version of the Sonia web interface that may be vulnerable to a stack buffer overflow. Dahua IP camera products include an application known as Sonia (/usr/bin/sonia) that provides the web interface and other services for controlling the IP camera remotely. Versions of Sonia included in firmware versions prior to DH_IPC-Consumer-Zi-Themis_Eng_P_V2.408.0000.11.R.20170621 do not validate input data length for the 'password' field of the web interface. A remote, unauthenticated attacker may submit a crafted POST request to the IP camera's Sonia web interface that may lead to out-of-bounds memory operations and loss of availability or remote code execution. The issue was originally identified by the researcher in firmware version DH_IPC-HX1X2X-Themis_EngSpnFrn_N_V2.400.0000.30.R.20160803.
- Source
- cret@cert.org
- NVD status
- Modified
Risk scores
CVSS 3.0
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:dahuasecurity:ip_camera_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "43A5DA4C-934D-4C9B-8246-8E729219D552", "versionEndExcluding": "dh_ipc-ack-themis_eng_p_v2.400.0000.14.r.20170713.bin" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:dahuasecurity:ip_camera:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "3C1DB735-F54C-4E47-BC00-C246E4C5911B" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:dahuasecurity:ip_camera_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "82BABFE4-CA54-432F-A91A-B09CDE3C5AB8", "versionEndExcluding": "2.400.0000.14.r.20170713" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:dahuasecurity:ip_camera:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "3C1DB735-F54C-4E47-BC00-C246E4C5911B" } ], "operator": "OR" } ], "operator": "AND" } ]