SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-9501

Attackers can obtain Cloud Key information from the Dahua Web P2P control in specific ways.

MEDIUM 5.5EPSS 0.34%

Does this matter?

Lower severity and a low EPSS score (0.34%). Track it; it rarely justifies an emergency change on its own.

Description

Attackers can obtain Cloud Key information from the Dahua Web P2P control in specific ways. Cloud Key is used to authenticate the connection between the client tool and the platform. An attacker may use the leaked Cloud Key to impersonate the client to connect to the platform, resulting in additional consumption of platform server resources. Versions with Build time before April 2020 are affected.

CVSS 3.1
5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
0.34% probability · 27th percentile
CISA KEV
Not listed
Affected
dahuasecurity/web p2p
Source
cybersecurity@dahuatech.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.