¡¾Â©¶´Í¨¸æ¡¿´ó»ªÉãÏñ»úδÊÚȨ·ÃÎÊ©¶´£¨CVE-2022-30564£©

Ðû²¼Ê±¼ä 2023-02-10

 

0x00 ©¶´¸ÅÊö

CVE   ID

CVE-2022-30564

·¢ÏÖʱ¼ä

2023-02-10

Àà    ÐÍ

δÊÚȨ²Ù×÷

µÈ    ¼¶

ÖÐΣ

Ô¶³ÌÀûÓÃ

ÊÇ

ËùÐèȨÏÞ

ÎÞ

¹¥»÷ÅÓ´ó¶È

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP


ÔÚÒ°ÀûÓÃ


 

0x01 ©¶´ÏêÇé

Õã½­´ó»ª¼¼Êõ¹É·ÝÓÐÏÞ¹«Ë¾ÊÇÁìÏÈµÄ¼à¿Ø²úÎ﹩ӦÉ̺ͽâ¾ö·½°¸ÌṩÉÌ£¬ÃæÏòÈ«ÇòÌṩÁìÏȵÄÊÓÆµ´æ´¢¡¢Ç°¶Ë¡¢ÏÔʾ¿ØÖƺÍÖÇÄܽ»Í¨µÈϵÁл¯²úÎï¡£

2ÔÂ8ÈÕ£¬´ó»ªÐû²¼Äþ¾²Í¨¸æ£¬ÐÞ¸´ÁËÆä¶à¸ö²úÎïÖеÄÒ»¸öδÊÚȨ²Ù×÷©¶´£¨CVE-2022-30564£©£¬¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ5.3¡£

ijЩ´ó»ªÇ¶Èëʽ²úÎï´æÔÚδÊÚȨ²Ù×÷©¶´£¬¸Ã©¶´ÊÇÓÉÓÚ´¦ÖÃʱ¼ä´Á±ä»¯µÄAPIδ¾­¹ýÑéÖ¤£¬Á˽âAPIÖ§³ÖµÄ²ÎÊýµÄÍþвÕß¿ÉÒÔͨ¹ýÏòÒ×Êܹ¥»÷µÄ½Ó¿Ú·¢ËÍÌØÖÆµÄÊý¾Ý°üÀ´ÐÞ¸ÄÉ豸µÄϵͳʱ¼ä¡£

ÀÖ³ÉÀûÓøÃ©¶´½«µ¼Ö´ó»ªÉãÏñ»úʱ¼ä´Á·¢Éú±ä»¯£¬ÕâÒâζ×Å¿ÉÒÔÐÞ¸ÄÊÓÆµÔ´µÄʱ¼ä´Á£¬µ¼ÖÂÂ¼ÖÆÊÓÆµÉÏ·ºÆð·×ÆçÖµÄÈÕÆÚºÍʱ¼ä£¬¶øÎÞÐèÖªµÀÉãÏñ»úµÄÓû§ÃûºÍÃÜÂ룬Õâ¶ÔÊý×Öȡ֤ÓÐÖ±½ÓÓ°Ïì¡£

 

Ó°Ï췶Χ

ÊÜÓ°ÏìÐͺÅ

ÊÜÓ°Ïì°æ±¾

Èí¼þÐÞ¸´

IPC-HX5XXX

IPC-HX7XXX

¹¹½¨Ê±¼ä½éÓÚ2018/12/01¨C2020/12/21Ö®¼äµÄ°æ±¾

DH_IPC-HFW7XXX-E3-Fafnir_MultiLang_PN_Stream4_V2.800.0000000.4.R.210708.zip

DH_IPC-HX5XXX-Volt_MultiLang_PN_Stream3_V2.840.0000000.18.R.220629.zip

DH_IPC-HX5XXX-Volt_MultiLang_NP_Stream3_V2.840.0000000.18.R.220629.zip

SD5A

SD22

SD59

¹¹½¨Ê±¼ä½éÓÚ2018/10/27   - 2021/05/08Ö®¼äµÄ°æ±¾

DH_SD-Prometheus_MultiLang_PN_Stream3_V2.812.0000032.2.R.220804.zip

DH_SD-Prometheus_MultiLang_NP_Stream3_V2.812.0000032.2.R.220804.zip

DH_SD-Eos-Civil_MultiLang_PN_Stream3_V2.813.0000017.0.R.220928.zip

DH_SD-Eos-Civil_MultiLang_NP_Stream3_V2.813.0000017.0.R.220928.zip

DH_SD-Eos_MultiLang_PN_Stream3_V2.812.0000017.0.R.220928.zip

DH_SD-Eos_MultiLang_NP_Stream3_V2.812.0000017.0.R.220928.zip

NVR5XXX-I

NVR5XXX-I/L

NVR4XXX-I

NVR2XXX-I

¹¹½¨Ê±¼ä½éÓÚ2018/04/29   - 2021/05/12Ö®¼äµÄ°æ±¾

DH_NVR5XXX-I_MultiLang_V4.002.0000000.3.R.221122.zip

DH_NVR5XXX-IL_MultiLang_V4.002.0000000.4.R.221122.zip

DH_NVR4XXX-I_MultiLang_V4.002.0000000.3.R.221122.zip

DH_NVR2XXX-I_Mul_V4.002.0000000.3.R.221122.zip

XVRXXXX-I2

XVRXXXX-X

¹¹½¨Ê±¼ä½éÓÚ2019/06/15-   2021/10/24Ö®¼äµÄ°æ±¾

DH_XVR5x04-I2_MultiLang_V4.001.0000003.3.R.221124.zip

DH_XVR5x08-I2_MultiLang_V4.001.0000003.3.R.221124.zip

DH_XVR5x16-I2_MultiLang_V4.001.0000005.1.R.221123.zip

DH_XVR7x16-I2_MultiLang_V4.001.0000005.1.R.221123.zip

DH_XVR7x32-I2_MultiLang_V4.001.0000005.1.R.221123.zip

DH_XVR5x08-X_MultiLang_V4.001.0000000.16.R.221124.zip

DH_XVR5x16-X_MultiLang_V4.001.0000000.16.R.221124.zip

DH_XVR7x16-X_MultiLang_V4.001.0000000.16.R.221124.zip

DH_XVR4x04-X1(2.0)_MultiLang_V4.001.0000000.16.R.221124.zip

DH_XVR5x04-X1(2.0)_MultiLang_V4.001.0000000.16.R.221124.zip

DH_XVR5x08-I_MultiLang_V4.001.0000000.11.R.221124.zip

DH_XVR5x16-I_MultiLang_V4.001.0000000.11.R.221124.zip

DH_XVR7x16-I_MultiLang_V4.001.0000000.11.R.221124.zip

DH_XVR5x04-I_MultiLang_V4.001.0000000.11.R.221124.zip

 

×¢£º¿ÉµÇ¼É豸µÄWeb½çÃæÒÔ¼ì²ì¹¹½¨Ê±¼ä£¬¿ÉÒÔÔÚÉèÖÃ-ϵͳÐÅÏ¢-°æ±¾ÐÅÏ¢Ò³Ãæ£¨setting-systeminfo-version£©ÖÐÕÒµ½¸ÃÐÅÏ¢¡£

 

0x02 Äþ¾²½¨Òé

Ŀǰ¸Ã©¶´ÒѾ­ÐÞ¸´£¬ÊÜÓ°ÏìÓû§¿É´Ó´ó»ªÍøÕ¾ÏÂÔØÏàÓ¦µÄÐÞ¸´Èí¼þ£¨»ò¸ü¸ß°æ±¾£©£¬»òÁªÏµµ±µØ¼¼ÊõÖ§³Ö½øÐÐÉý¼¶¡£

ÏÂÔØÁ´½Ó£º

https://www.dahuasecurity.com/support/downloadCenter

 

0x03 ²Î¿¼Á´½Ó

https://www.dahuasecurity.com/support/cybersecurity/details/1147

https://www.redinent.com/blog/dahua-cve-2022-30564/

 

0x04 °æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2023-02-10

Ê×´ÎÐû²¼

  

0x05 ¸½Â¼

¶¶È¦Îª¶Ä¶øÉú¼ò½é

¶¶È¦Îª¶Ä¶øÉú½¨Á¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò»¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶¶È¦Îª¶Ä¶øÉú´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬¶¶È¦Îª¶Ä¶øÉúÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Å¬Á¦¡£

 

¹ØÓÚ¶¶È¦Îª¶Ä¶øÉú

¶¶È¦Îª¶Ä¶øÉúÄþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖØÒªÄþ¾²Â©¶´µÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÄþ¾²³ÂËß¡£

¹Ø×¢ÒÔϹ«Öںţ¬»ñȡȫÇò×îÐÂÄþ¾²×ÊѶ£º

image.png