¡¾Â©¶´Í¨¸æ¡¿´ó»ªÉãÏñ»úδÊÚȨ·ÃÎÊ©¶´£¨CVE-2022-30564£©
Ðû²¼Ê±¼ä 2023-02-10
0x00 ©¶´¸ÅÊö
CVE ID | CVE-2022-30564 | ·¢ÏÖʱ¼ä | 2023-02-10 |
Àà ÐÍ | δÊÚȨ²Ù×÷ | µÈ ¼¶ | ÖÐΣ |
Ô¶³ÌÀûÓà | ÊÇ | ËùÐèȨÏÞ | ÎÞ |
¹¥»÷ÅÓ´ó¶È | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | ÔÚÒ°ÀûÓÃ |
0x01 ©¶´ÏêÇé
Õ㽴󻪼¼Êõ¹É·ÝÓÐÏÞ¹«Ë¾ÊÇÁìÏÈµÄ¼à¿Ø²úÎ﹩ӦÉ̺ͽâ¾ö·½°¸ÌṩÉÌ£¬ÃæÏòÈ«ÇòÌṩÁìÏȵÄÊÓÆµ´æ´¢¡¢Ç°¶Ë¡¢ÏÔʾ¿ØÖƺÍÖÇÄܽ»Í¨µÈϵÁл¯²úÎï¡£
2ÔÂ8ÈÕ£¬´ó»ªÐû²¼Äþ¾²Í¨¸æ£¬ÐÞ¸´ÁËÆä¶à¸ö²úÎïÖеÄÒ»¸öδÊÚȨ²Ù×÷©¶´£¨CVE-2022-30564£©£¬¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ5.3¡£
ijЩ´ó»ªÇ¶Èëʽ²úÎï´æÔÚδÊÚȨ²Ù×÷©¶´£¬¸Ã©¶´ÊÇÓÉÓÚ´¦ÖÃʱ¼ä´Á±ä»¯µÄAPIδ¾¹ýÑéÖ¤£¬Á˽âAPIÖ§³ÖµÄ²ÎÊýµÄÍþвÕß¿ÉÒÔͨ¹ýÏòÒ×Êܹ¥»÷µÄ½Ó¿Ú·¢ËÍÌØÖÆµÄÊý¾Ý°üÀ´ÐÞ¸ÄÉ豸µÄϵͳʱ¼ä¡£
ÀÖ³ÉÀûÓøÃ©¶´½«µ¼Ö´ó»ªÉãÏñ»úʱ¼ä´Á·¢Éú±ä»¯£¬ÕâÒâζ×Å¿ÉÒÔÐÞ¸ÄÊÓÆµÔ´µÄʱ¼ä´Á£¬µ¼ÖÂÂ¼ÖÆÊÓÆµÉÏ·ºÆð·×ÆçÖµÄÈÕÆÚºÍʱ¼ä£¬¶øÎÞÐèÖªµÀÉãÏñ»úµÄÓû§ÃûºÍÃÜÂ룬Õâ¶ÔÊý×Öȡ֤ÓÐÖ±½ÓÓ°Ïì¡£
Ó°Ï췶Χ
ÊÜÓ°ÏìÐͺŠ| ÊÜÓ°Ïì°æ±¾ | Èí¼þÐÞ¸´ |
IPC-HX5XXX IPC-HX7XXX | ¹¹½¨Ê±¼ä½éÓÚ2018/12/01¨C2020/12/21Ö®¼äµÄ°æ±¾ | DH_IPC-HFW7XXX-E3-Fafnir_MultiLang_PN_Stream4_V2.800.0000000.4.R.210708.zip DH_IPC-HX5XXX-Volt_MultiLang_PN_Stream3_V2.840.0000000.18.R.220629.zip DH_IPC-HX5XXX-Volt_MultiLang_NP_Stream3_V2.840.0000000.18.R.220629.zip |
SD5A SD22 SD59 | ¹¹½¨Ê±¼ä½éÓÚ2018/10/27 - 2021/05/08Ö®¼äµÄ°æ±¾ | DH_SD-Prometheus_MultiLang_PN_Stream3_V2.812.0000032.2.R.220804.zip DH_SD-Prometheus_MultiLang_NP_Stream3_V2.812.0000032.2.R.220804.zip DH_SD-Eos-Civil_MultiLang_PN_Stream3_V2.813.0000017.0.R.220928.zip DH_SD-Eos-Civil_MultiLang_NP_Stream3_V2.813.0000017.0.R.220928.zip DH_SD-Eos_MultiLang_PN_Stream3_V2.812.0000017.0.R.220928.zip DH_SD-Eos_MultiLang_NP_Stream3_V2.812.0000017.0.R.220928.zip |
NVR5XXX-I NVR5XXX-I/L NVR4XXX-I NVR2XXX-I | ¹¹½¨Ê±¼ä½éÓÚ2018/04/29 - 2021/05/12Ö®¼äµÄ°æ±¾ | DH_NVR5XXX-I_MultiLang_V4.002.0000000.3.R.221122.zip DH_NVR5XXX-IL_MultiLang_V4.002.0000000.4.R.221122.zip DH_NVR4XXX-I_MultiLang_V4.002.0000000.3.R.221122.zip DH_NVR2XXX-I_Mul_V4.002.0000000.3.R.221122.zip |
XVRXXXX-I2 XVRXXXX-X | ¹¹½¨Ê±¼ä½éÓÚ2019/06/15- 2021/10/24Ö®¼äµÄ°æ±¾ | DH_XVR5x04-I2_MultiLang_V4.001.0000003.3.R.221124.zip DH_XVR5x08-I2_MultiLang_V4.001.0000003.3.R.221124.zip DH_XVR5x16-I2_MultiLang_V4.001.0000005.1.R.221123.zip DH_XVR7x16-I2_MultiLang_V4.001.0000005.1.R.221123.zip DH_XVR7x32-I2_MultiLang_V4.001.0000005.1.R.221123.zip DH_XVR5x08-X_MultiLang_V4.001.0000000.16.R.221124.zip DH_XVR5x16-X_MultiLang_V4.001.0000000.16.R.221124.zip DH_XVR7x16-X_MultiLang_V4.001.0000000.16.R.221124.zip DH_XVR4x04-X1(2.0)_MultiLang_V4.001.0000000.16.R.221124.zip DH_XVR5x04-X1(2.0)_MultiLang_V4.001.0000000.16.R.221124.zip DH_XVR5x08-I_MultiLang_V4.001.0000000.11.R.221124.zip DH_XVR5x16-I_MultiLang_V4.001.0000000.11.R.221124.zip DH_XVR7x16-I_MultiLang_V4.001.0000000.11.R.221124.zip DH_XVR5x04-I_MultiLang_V4.001.0000000.11.R.221124.zip |
×¢£º¿ÉµÇ¼É豸µÄWeb½çÃæÒÔ¼ì²ì¹¹½¨Ê±¼ä£¬¿ÉÒÔÔÚÉèÖÃ-ϵͳÐÅÏ¢-°æ±¾ÐÅÏ¢Ò³Ãæ£¨setting-systeminfo-version£©ÖÐÕÒµ½¸ÃÐÅÏ¢¡£
0x02 Äþ¾²½¨Òé
Ŀǰ¸Ã©¶´ÒѾÐÞ¸´£¬ÊÜÓ°ÏìÓû§¿É´Ó´ó»ªÍøÕ¾ÏÂÔØÏàÓ¦µÄÐÞ¸´Èí¼þ£¨»ò¸ü¸ß°æ±¾£©£¬»òÁªÏµµ±µØ¼¼ÊõÖ§³Ö½øÐÐÉý¼¶¡£
ÏÂÔØÁ´½Ó£º
https://www.dahuasecurity.com/support/downloadCenter
0x03 ²Î¿¼Á´½Ó
https://www.dahuasecurity.com/support/cybersecurity/details/1147
https://www.redinent.com/blog/dahua-cve-2022-30564/
0x04 °æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2023-02-10 | Ê×´ÎÐû²¼ |
0x05 ¸½Â¼
¶¶È¦Îª¶Ä¶øÉú¼ò½é
¶¶È¦Îª¶Ä¶øÉú½¨Á¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò»¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶¶È¦Îª¶Ä¶øÉú´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬¶¶È¦Îª¶Ä¶øÉúÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Å¬Á¦¡£
¹ØÓÚ¶¶È¦Îª¶Ä¶øÉú
¶¶È¦Îª¶Ä¶øÉúÄþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖØÒªÄþ¾²Â©¶´µÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÄþ¾²³ÂËß¡£
¹Ø×¢ÒÔϹ«Öںţ¬»ñȡȫÇò×îÐÂÄþ¾²×ÊѶ£º