RULE(RULE ID:338168)

Rule General Information
Release Date: 2024-06-25
Rule Name: Dahua ICC random Remote Code Execution Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Dahua ICC Intelligent things integrated management platform is a comprehensive management platform that integrates advanced technologies such as Internet of things technology, big data analysis, cloud computing and so on. Dahua ICC intelligent things integrated management platform has a remote code execution vulnerability. The vulnerability is caused by the random interface not filtering user input effectively, which leads to the fastjson deserialization vulnerability.
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.