CVE-2024-13130

A vulnerability was found in Dahua IPC-HFW1200S, IPC-HFW2300R-Z, IPC-HFW5220E-Z and IPC-HDW1200S up to 20241222. It has been rated as problematic. Affected by this issue is some unknown functionality of the file ../mtd/Config/Sha1Account1 of the component Web Interface. The manipulation leads to path traversal: '../filedir'. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Configurations

No configuration.

History

10 Jan 2025, 14:15

Type Values Removed Values Added
Summary
  • (es) Se ha detectado una vulnerabilidad en los modelos Dahua IPC-HFW1200S, IPC-HFW2300R-Z, IPC-HFW5220E-Z e IPC-HDW1200S hasta 20241222. Se ha calificado como problemática. Este problema afecta a una funcionalidad desconocida del archivo ../mtd/Config/Sha1Account1 del componente Web Interface. La manipulación conduce a una ruta de acceso: '../filedir'. El ataque puede ejecutarse de forma remota. El exploit se ha hecho público y puede utilizarse. Se contactó al proveedor con anticipación sobre esta revelación, pero no respondió de ninguna manera.
Summary (en) A vulnerability was found in Dahua IPC-HFW1200S, IPC-HFW2300R-Z, IPC-HFW5220E-Z and IPC-HDW1200S up to 20241222. It has been rated as problematic. Affected by this issue is some unknown functionality of the file ../mtd/Config/Sha1Account1 of the component Web Interface. The manipulation leads to path traversal: '../filedir'. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. (en) A vulnerability was found in Dahua IPC-HFW1200S, IPC-HFW2300R-Z, IPC-HFW5220E-Z and IPC-HDW1200S up to 20241222. It has been rated as problematic. Affected by this issue is some unknown functionality of the file ../mtd/Config/Sha1Account1 of the component Web Interface. The manipulation leads to path traversal: '../filedir'. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

05 Jan 2025, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-05 01:15

Updated : 2025-01-10 14:15


NVD link : CVE-2024-13130

Mitre link : CVE-2024-13130

CVE.ORG link : CVE-2024-13130


JSON object : View

Products Affected

No product.

CWE
CWE-23

Relative Path Traversal

CWE-24

Path Traversal: '../filedir'