RULE(RULE ID:338616)

Rule General Information
Release Date: 2024-12-24
Rule Name: DaHua DSS attachment_downloadAtt.action Arbitary File Read Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Dahua DSS digital monitoring system is designed and developed on the basis of common security video surveillance system, in addition to the common security video surveillance of real-time monitoring, head operation, video playback, alarm processing, equipment management and other functions, more consideration of how to facilitate the user to use the ergonomics of the system. An arbitrary file read vulnerability in the attachment\_downloadByUrlAtt.action interface could be exploited by an unauthenticated remote attacker to obtain sensitive internal file information, leaving the system in an extremely insecure state.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.