CVE-2022-45430 is a low-severity vulnerability affecting some Dahua software products, allowing an unauthenticated attacker to enable or disable the SSHD service. By sending a specially crafted packet to a vulnerable interface, an attacker could bypass firewall access controls, resulting in a low impact on integrity (I:L) and no impact on confidentiality or availability. This vulnerability has a CVSS score of 3.7 and is not currently listed on CISA's KEV catalog. There is no public exploit code available, nor has it garnered significant community discussion or media coverage, indicating a low likelihood of active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.002.1760000.2CPE matchmatch criteria | cpe:2.3:a:dahuasecurity:dss_express:7.002.1760000.2:*:*:*:*:*:*:* | ||
8.0.2CPE matchmatch criteria | cpe:2.3:a:dahuasecurity:dss_express:8.0.2:*:*:*:*:*:*:* | ||
8.0.4CPE matchmatch criteria | cpe:2.3:a:dahuasecurity:dss_express:8.0.4:*:*:*:*:*:*:* | ||
8.1CPE matchmatch criteria | cpe:2.3:a:dahuasecurity:dss_express:8.1:*:*:*:*:*:*:* | ||
8.1.1CPE matchmatch criteria | cpe:2.3:a:dahuasecurity:dss_express:8.1.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.