ID

VAR-202206-2212


CVE

CVE-2022-30560


TITLE

plural  Dahua Technology Co., Ltd  Product vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2022-012804

DESCRIPTION

When an attacker obtaining the administrative account and password, or through a man-in-the-middle attack, the attacker could send a specified crafted packet to the vulnerable interface then lead the device to crash. ipc-hdbw2431e-s-s2 firmware, ipc-hdbw2831e-s-s2 firmware, ipc-hdbw2230e-s-s2 firmware etc. Dahua Technology Co., Ltd There are unspecified vulnerabilities in the product.Information is obtained and service operation is interrupted (DoS) It may be in a state. Dahua IPC-HFW2XXX, etc. are all products of China Dahua (Dahua) company. Dahua IPC-HFW2XXX is an IP camera. Dahua IPC-HDBW2XXX is a series of cameras. Dahua ASI7XXXX is a series of face recognition access controller

Trust: 2.25

sources: NVD: CVE-2022-30560 // JVNDB: JVNDB-2022-012804 // CNVD: CNVD-2022-60683 // VULMON: CVE-2022-30560

IOT TAXONOMY

category:['IoT']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2022-60683

AFFECTED PRODUCTS

vendor:dahuasecuritymodel:ipc-hdbw2230e-s-s2scope:ltversion:2022-04

Trust: 1.0

vendor:dahuasecuritymodel:ipc-hdbw2831r-zas-s2scope:ltversion:2022-04

Trust: 1.0

vendor:dahuasecuritymodel:ipc-hfw2439s-sa-led-s2scope:ltversion:2022-04

Trust: 1.0

vendor:dahuasecuritymodel:ipc-hfw2231t-zas-s2scope:ltversion:2022-04

Trust: 1.0

vendor:dahuasecuritymodel:asi7223x-a-t1scope:ltversion:2021-09

Trust: 1.0

vendor:dahuasecuritymodel:ipc-hfw2531t-zas-s2scope:ltversion:2022-04

Trust: 1.0

vendor:dahuasecuritymodel:ipc-hdbw2531r-zs-s2scope:ltversion:2022-04

Trust: 1.0

vendor:dahuasecuritymodel:ipc-hdbw2431r-zas-s2scope:ltversion:2022-04

Trust: 1.0

vendor:dahuasecuritymodel:ipc-hfw2831t-zas-s2scope:ltversion:2022-04

Trust: 1.0

vendor:dahuasecuritymodel:ipc-hfw2831t-as-s2scope:ltversion:2022-04

Trust: 1.0

vendor:dahuasecuritymodel:ipc-hfw2431s-s-s2scope:ltversion:2022-04

Trust: 1.0

vendor:dahuasecuritymodel:asi7213x-t1scope:ltversion:2021-09

Trust: 1.0

vendor:dahuasecuritymodel:ipc-hdbw2831r-zs-s2scope:ltversion:2022-04

Trust: 1.0

vendor:dahuasecuritymodel:ipc-hfw2231s-s-s2scope:ltversion:2022-04

Trust: 1.0

vendor:dahuasecuritymodel:ipc-hdbw2531r-zas-s2scope:ltversion:2022-04

Trust: 1.0

vendor:dahuasecuritymodel:ipc-hdbw2231e-s-s2scope:ltversion:2022-04

Trust: 1.0

vendor:dahuasecuritymodel:ipc-hfw2831s-s-s2scope:ltversion:2022-04

Trust: 1.0

vendor:dahuasecuritymodel:ipc-hfw2531s-s-s2scope:ltversion:2022-04

Trust: 1.0

vendor:dahuasecuritymodel:ipc-hfw2231m-as-i2-b-s2scope:ltversion:2022-04

Trust: 1.0

vendor:dahuasecuritymodel:ipc-hfw2230s-s-s2scope:ltversion:2022-04

Trust: 1.0

vendor:dahuasecuritymodel:ipc-hdbw2431r-zs-s2scope:ltversion:2022-04

Trust: 1.0

vendor:dahuasecuritymodel:ipc-hdbw2531e-s-s2scope:ltversion:2022-04

Trust: 1.0

vendor:dahuasecuritymodel:ipc-hdbw2831e-s-s2scope:ltversion:2022-04

Trust: 1.0

vendor:dahuasecuritymodel:ipc-hdbw2431e-s-s2scope:ltversion:2022-04

Trust: 1.0

vendor:dahuasecuritymodel:asi7223x-ascope:ltversion:2021-09

Trust: 1.0

vendor:dahuasecuritymodel:ipc-hfw2439m-as-led-b-s2scope:ltversion:2022-04

Trust: 1.0

vendor:dahuasecuritymodel:ipc-hfw2239s-sa-led-s2scope:ltversion:2022-04

Trust: 1.0

vendor:dahuasecuritymodel:ipc-hfw2431t-as-s2scope:ltversion:2022-04

Trust: 1.0

vendor:dahuasecuritymodel:ipc-hdbw2231r-zs-s2scope:ltversion:2022-04

Trust: 1.0

vendor:dahuasecuritymodel:ipc-hfw2531t-zs-s2scope:ltversion:2022-04

Trust: 1.0

vendor:dahuasecuritymodel:ipc-hfw2239m-as-led-b-s2scope:ltversion:2022-04

Trust: 1.0

vendor:dahuasecuritymodel:ipc-hfw2531t-as-s2scope:ltversion:2022-04

Trust: 1.0

vendor:dahuasecuritymodel:ipc-hdbw2231r-zas-s2scope:ltversion:2022-04

Trust: 1.0

vendor:dahuasecuritymodel:ipc-hfw2431t-zas-s2scope:ltversion:2022-04

Trust: 1.0

vendor:dahuasecuritymodel:ipc-hdbw2231f-as-s2scope:ltversion:2022-04

Trust: 1.0

vendor:dahuasecuritymodel:ipc-hfw2231t-as-s2scope:ltversion:2022-04

Trust: 1.0

vendor:dahuasecuritymodel:ipc-hfw2231t-zs-s2scope:ltversion:2022-04

Trust: 1.0

vendor:dahuasecuritymodel:ipc-hfw2831t-zs-s2scope:ltversion:2022-04

Trust: 1.0

vendor:dahuasecuritymodel:asi7213xscope:ltversion:2021-09

Trust: 1.0

vendor:dahuasecuritymodel:ipc-hfw2431t-zs-s2scope:ltversion:2022-04

Trust: 1.0

vendor:dahuamodel:ipc-hdbw2431e-s-s2scope: - version: -

Trust: 0.8

vendor:dahuamodel:ipc-hdbw2231e-s-s2scope: - version: -

Trust: 0.8

vendor:dahuamodel:ipc-hfw2231t-zs-s2scope: - version: -

Trust: 0.8

vendor:dahuamodel:ipc-hfw2231t-zas-s2scope: - version: -

Trust: 0.8

vendor:dahuamodel:ipc-hdbw2231r-zs-s2scope: - version: -

Trust: 0.8

vendor:dahuamodel:ipc-hdbw2231f-as-s2scope: - version: -

Trust: 0.8

vendor:dahuamodel:ipc-hdbw2531e-s-s2scope: - version: -

Trust: 0.8

vendor:dahuamodel:ipc-hdbw2231r-zas-s2scope: - version: -

Trust: 0.8

vendor:dahuamodel:ipc-hdbw2831r-zs-s2scope: - version: -

Trust: 0.8

vendor:dahuamodel:ipc-hdbw2831e-s-s2scope: - version: -

Trust: 0.8

vendor:dahuamodel:ipc-hdbw2431r-zs-s2scope: - version: -

Trust: 0.8

vendor:dahuamodel:ipc-hdbw2531r-zs-s2scope: - version: -

Trust: 0.8

vendor:dahuamodel:ipc-hfw2231t-as-s2scope: - version: -

Trust: 0.8

vendor:dahuamodel:ipc-hfw2231m-as-i2-b-s2scope: - version: -

Trust: 0.8

vendor:dahuamodel:ipc-hdbw2831r-zas-s2scope: - version: -

Trust: 0.8

vendor:dahuamodel:ipc-hdbw2431r-zas-s2scope: - version: -

Trust: 0.8

vendor:dahuamodel:ipc-hdbw2531r-zas-s2scope: - version: -

Trust: 0.8

vendor:dahuamodel:ipc-hdbw2230e-s-s2scope: - version: -

Trust: 0.8

vendor:dahuamodel:ipc-hfw2231s-s-s2scope: - version: -

Trust: 0.8

vendor:dahuamodel:ipc-hdbw2xxxscope: - version: -

Trust: 0.6

vendor:dahuamodel:ipc-hfw2xxxscope: - version: -

Trust: 0.6

vendor:dahuamodel:asi7xxxxscope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2022-60683 // JVNDB: JVNDB-2022-012804 // NVD: CVE-2022-30560

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2022-30560
value: HIGH

Trust: 1.0

NVD: CVE-2022-30560
value: HIGH

Trust: 0.8

CNVD: CNVD-2022-60683
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-202206-2720
value: HIGH

Trust: 0.6

nvd@nist.gov: CVE-2022-30560
severity: MEDIUM
baseScore: 5.8
vectorString: AV:N/AC:M/AU:N/C:P/I:N/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2022-60683
severity: MEDIUM
baseScore: 5.8
vectorString: AV:N/AC:M/AU:N/C:P/I:N/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2022-30560
baseSeverity: HIGH
baseScore: 7.4
vectorString: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H
attackVector: NETWORK
attackComplexity: HIGH
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 2.2
impactScore: 5.2
version: 3.1

Trust: 1.0

NVD: CVE-2022-30560
baseSeverity: HIGH
baseScore: 7.4
vectorString: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H
attackVector: NETWORK
attackComplexity: HIGH
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2022-60683 // JVNDB: JVNDB-2022-012804 // CNNVD: CNNVD-202206-2720 // NVD: CVE-2022-30560

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:Lack of information (CWE-noinfo) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2022-012804 // NVD: CVE-2022-30560

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202206-2720

TYPE

code problem

Trust: 0.6

sources: CNNVD: CNNVD-202206-2720

PATCH

title:Patch for Denial of Service Vulnerabilities in Several Dahua Productsurl:https://www.cnvd.org.cn/patchInfo/show/347711

Trust: 0.6

title:Multiple Dahua Product code issue vulnerability fixesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=200882

Trust: 0.6

sources: CNVD: CNVD-2022-60683 // CNNVD: CNNVD-202206-2720

EXTERNAL IDS

db:NVDid:CVE-2022-30560

Trust: 3.9

db:JVNDBid:JVNDB-2022-012804

Trust: 0.8

db:CNVDid:CNVD-2022-60683

Trust: 0.6

db:ICS CERTid:ICSA-22-193-01

Trust: 0.6

db:CNNVDid:CNNVD-202206-2720

Trust: 0.6

db:VULMONid:CVE-2022-30560

Trust: 0.1

sources: CNVD: CNVD-2022-60683 // VULMON: CVE-2022-30560 // JVNDB: JVNDB-2022-012804 // CNNVD: CNNVD-202206-2720 // NVD: CVE-2022-30560

REFERENCES

url:https://www.dahuasecurity.com/support/cybersecurity/details/1017

Trust: 2.5

url:https://cxsecurity.com/cveshow/cve-2022-30560/

Trust: 1.2

url:https://nvd.nist.gov/vuln/detail/cve-2022-30560

Trust: 0.8

url:https://us-cert.cisa.gov/ics/advisories/icsa-22-193-01

Trust: 0.6

url:https://nvd.nist.gov

Trust: 0.1

sources: CNVD: CNVD-2022-60683 // VULMON: CVE-2022-30560 // JVNDB: JVNDB-2022-012804 // CNNVD: CNNVD-202206-2720 // NVD: CVE-2022-30560

CREDITS

Nozomi Networks reported these vulnerabilities to CISA.

Trust: 0.6

sources: CNNVD: CNNVD-202206-2720

SOURCES

db:CNVDid:CNVD-2022-60683
db:VULMONid:CVE-2022-30560
db:JVNDBid:JVNDB-2022-012804
db:CNNVDid:CNNVD-202206-2720
db:NVDid:CVE-2022-30560

LAST UPDATE DATE

2024-08-14T12:22:43.861000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2022-60683date:2022-08-31T00:00:00
db:VULMONid:CVE-2022-30560date:2022-06-28T00:00:00
db:JVNDBid:JVNDB-2022-012804date:2023-09-01T08:16:00
db:CNNVDid:CNNVD-202206-2720date:2022-07-29T00:00:00
db:NVDid:CVE-2022-30560date:2022-07-13T17:38:30.007

SOURCES RELEASE DATE

db:CNVDid:CNVD-2022-60683date:2022-08-31T00:00:00
db:VULMONid:CVE-2022-30560date:2022-06-28T00:00:00
db:JVNDBid:JVNDB-2022-012804date:2023-09-01T00:00:00
db:CNNVDid:CNNVD-202206-2720date:2022-06-28T00:00:00
db:NVDid:CVE-2022-30560date:2022-06-28T14:15:08.087