Loading
Generated remediation guidance and an executive summary. No account required.
Online upgrade information in some firmware packages of Dahua products is not encrypted. Attackers can obtain this information by analyzing firmware packages by specific means. Affected products include: IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X,IPC-HFW2X2X,IPC-HDW4X2X,IPC-HFW4X2X,IPC-HDBW4X2X,IPC-HDW5X2X,IPC-HFW5X2X for versions which Build time is before August 18,2019.
Use CWE-311, Dahuasecurity vendor hub and Ipc-Hdw1x2x Firmware product page to widen CVE-2019-9681 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2019-9677, CVE-2019-9679 and CVE-2019-9678 for nearby disclosures in the same product family.