Sd50 Firmware

Vendor:

First CVE: Apr 9, 2020 · Active for 6 years

6
Total CVEs
More Total CVEs than 83% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 63% of tracked products
8.3
Avg CVSS
Higher Avg CVSS than 75% of tracked products
16.7%
KEV Rate
Higher KEV Rate than 99% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Sd50 Firmware over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 9, 2020
6 years ago
Most Recent CVE
Jan 13, 2022
1,657 days ago

CVE Severity & Scoring

Sd50 Firmware6 CVEs
All CVEs353,240 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network6 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (83.3%)
High1 (16.7%)
Unknown0 (0.0%)
User Interaction
None6 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High2 (33.3%)
None4 (66.7%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing maliciou
Sep 15, 20219.898YESYES
Some Dahua products with Build time before December 2019 have Session ID predictable vulnerabilities. During normal user access, an attacker can use the predicted Session ID to con
May 13, 20209.830NONO
Some Dahua products have access control vulnerability in the password reset process. Attackers can exploit this vulnerability through specific deployments to reset device passwords
Jan 13, 20229.829NONO
Some Dahua products have buffer overflow vulnerabilities. After the successful login of the legal account, the attacker sends a specific DDNS test command, which may cause the devi
Apr 9, 20207.225NONO
Dahua devices with Build time before December 2019 use strong security login mode by default, but in order to be compatible with the normal login of early devices, some devices ret
May 13, 20208.120NONO
Some products of Dahua have Denial of Service vulnerabilities. After the successful login of the legal account, the attacker sends a specific log query command, which may cause the
Apr 9, 20204.920NONO

Exploit Exposure

Signals from CVEs in this product scope (6 CVEs).

CISA KEV
1 CVE
16.7% of CVEs· 99th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
16.7% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (6 CVEs).

Media Mentions

Signals from CVEs in this product scope (6 CVEs).

Top CNAs Publishing CVEs For Sd50 Firmware

Top CWEs

Versions

No cataloged versions.