¡¾·ì϶¹«¸æ¡¿´ó»ªÉãÏñ»úδÊÚȨ½Ó¼û·ì϶£¨CVE-2022-30564£©

°ä²¼¹¦·ò 2023-02-10

 

0x00 ·ì϶¸ÅÊö

CVE   ID

CVE-2022-30564

·¢ÏÖ¹¦·ò

2023-02-10

Àà    ÐÍ

δÊÚȨ²Ù×÷

µÈ    ¼¶

ÖÐΣ

Ô¶³ÌÀûÓÃ

ÊÇ

ËùÐèȨÏÞ

ÎÞ

¹¥»÷¸´ÔÓ¶È

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP


ÔÚÒ°ÀûÓÃ


 

0x01 ·ì϶ÏêÇé

Õã½­´ó»ª¼¼Êõ¹É·ÝÓÐÏÞ¹«Ë¾Êǵ±ÏÈµÄ¼à¿Ø²úÆ·¹©¸øÉ̺ͽâ¾ö¹æ»®ÌṩÉÌ£¬ÃæÏòÈ«ÇòÌṩµ±ÏȵÄÊÓÆµ´æ´¢¡¢Ç°¶Ë¡¢ÏÔʾ½ÚÔìºÍÖÇÄܽ»Í¨µÈϵÁл¯²úÆ·  ¡£

2ÔÂ8ÈÕ£¬´ó»ª°ä²¼°²È«²¼¸æ£¬½¨¸´ÁËÆä¶à¸ö²úÆ·ÖеÄÒ»¸öδÊÚȨ²Ù×÷·ì϶£¨CVE-2022-30564£©£¬¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ5.3  ¡£

ijЩ´ó»ªÇ¶Èëʽ²úÆ·´æÔÚδÊÚȨ²Ù×÷·ì϶£¬¸Ã·ì϶ÊÇÓÉÓÚ´¦Öù¦·ò´Á±ä¶¯µÄAPIδ¾­¹ýÑéÖ¤£¬ÏàʶAPIÖ§³ÖµÄ²ÎÊýµÄÍþвÕßÄܹ»Í¨¹ýÏòÒ×Êܹ¥»÷µÄ½Ó¿Ú·¢ËÍÌØÔìµÄÊý¾Ý°üÀ´Åú¸ÄÉ豸µÄϵͳ¹¦·ò  ¡£

³É¹¦ÀûÓø÷ì϶½«µ¼Ö´ó»ªÉãÏñ»ú¹¦·ò´Á²úÉú±ä¶¯£¬ÕâÒâζ×ÅÄܹ»Åú¸ÄÊÓÆµÔ´µÄ¹¦·ò´Á£¬µ¼Ö¼ÔìÊÓÆµÉϳöÏÖ²»Ò»ÖµÄÈÕÆÚºÍ¹¦·ò£¬¶øÎÞÐè֪·ÉãÏñ»úµÄÓû§ÃûºÍÃÜÂ룬Õâ¶ÔÊý×Öȡ֤ÓÐÖ±½ÓÓ°Ïì  ¡£

 

Ó°ÏìÁìÓò

ÊÜÓ°ÏìÐͺÅ

ÊÜÓ°Ïì°æ±¾

Èí¼þ½¨¸´

IPC-HX5XXX

IPC-HX7XXX

¹¹½¨¹¦·ò½éÓÚ2018/12/01¨C2020/12/21Ö®¼äµÄ°æ±¾

DH_IPC-HFW7XXX-E3-Fafnir_MultiLang_PN_Stream4_V2.800.0000000.4.R.210708.zip

DH_IPC-HX5XXX-Volt_MultiLang_PN_Stream3_V2.840.0000000.18.R.220629.zip

DH_IPC-HX5XXX-Volt_MultiLang_NP_Stream3_V2.840.0000000.18.R.220629.zip

SD5A

SD22

SD59

¹¹½¨¹¦·ò½éÓÚ2018/10/27   - 2021/05/08Ö®¼äµÄ°æ±¾

DH_SD-Prometheus_MultiLang_PN_Stream3_V2.812.0000032.2.R.220804.zip

DH_SD-Prometheus_MultiLang_NP_Stream3_V2.812.0000032.2.R.220804.zip

DH_SD-Eos-Civil_MultiLang_PN_Stream3_V2.813.0000017.0.R.220928.zip

DH_SD-Eos-Civil_MultiLang_NP_Stream3_V2.813.0000017.0.R.220928.zip

DH_SD-Eos_MultiLang_PN_Stream3_V2.812.0000017.0.R.220928.zip

DH_SD-Eos_MultiLang_NP_Stream3_V2.812.0000017.0.R.220928.zip

NVR5XXX-I

NVR5XXX-I/L

NVR4XXX-I

NVR2XXX-I

¹¹½¨¹¦·ò½éÓÚ2018/04/29   - 2021/05/12Ö®¼äµÄ°æ±¾

DH_NVR5XXX-I_MultiLang_V4.002.0000000.3.R.221122.zip

DH_NVR5XXX-IL_MultiLang_V4.002.0000000.4.R.221122.zip

DH_NVR4XXX-I_MultiLang_V4.002.0000000.3.R.221122.zip

DH_NVR2XXX-I_Mul_V4.002.0000000.3.R.221122.zip

XVRXXXX-I2

XVRXXXX-X

¹¹½¨¹¦·ò½éÓÚ2019/06/15-   2021/10/24Ö®¼äµÄ°æ±¾

DH_XVR5x04-I2_MultiLang_V4.001.0000003.3.R.221124.zip

DH_XVR5x08-I2_MultiLang_V4.001.0000003.3.R.221124.zip

DH_XVR5x16-I2_MultiLang_V4.001.0000005.1.R.221123.zip

DH_XVR7x16-I2_MultiLang_V4.001.0000005.1.R.221123.zip

DH_XVR7x32-I2_MultiLang_V4.001.0000005.1.R.221123.zip

DH_XVR5x08-X_MultiLang_V4.001.0000000.16.R.221124.zip

DH_XVR5x16-X_MultiLang_V4.001.0000000.16.R.221124.zip

DH_XVR7x16-X_MultiLang_V4.001.0000000.16.R.221124.zip

DH_XVR4x04-X1(2.0)_MultiLang_V4.001.0000000.16.R.221124.zip

DH_XVR5x04-X1(2.0)_MultiLang_V4.001.0000000.16.R.221124.zip

DH_XVR5x08-I_MultiLang_V4.001.0000000.11.R.221124.zip

DH_XVR5x16-I_MultiLang_V4.001.0000000.11.R.221124.zip

DH_XVR7x16-I_MultiLang_V4.001.0000000.11.R.221124.zip

DH_XVR5x04-I_MultiLang_V4.001.0000000.11.R.221124.zip

 

×¢£º¿ÉµÇ¼É豸µÄWeb½çÃæÒԲ鿴¹¹½¨¹¦·ò£¬Äܹ»ÔÚÉèÖÃ-ϵͳÐÅÏ¢-°æ±¾ÐÅÏ¢Ò³Ãæ£¨setting-systeminfo-version£©ÖÐÕÒµ½¸ÃÐÅÏ¢  ¡£

 

0x02 °²È«½¨Òé

Ŀǰ¸Ã·ì϶ÒѾ­½¨¸´£¬ÊÜÓ°ÏìÓû§¿É´Ó´ó»ªÍøÕ¾ÏÂÔØÏàÓ¦µÄ½¨¸´Èí¼þ£¨»ò¸ü¸ß°æ±¾£©£¬»òÁªÏµ±¾µØ¼¼ÊõÖ§³Ö½øÐÐÉý¼¶  ¡£

ÏÂÔØÁ´½Ó£º

https://www.dahuasecurity.com/support/downloadCenter

 

0x03 ²Î¿¼Á´½Ó

https://www.dahuasecurity.com/support/cybersecurity/details/1147

https://www.redinent.com/blog/dahua-cve-2022-30564/

 

0x04 °æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

Åú¸ÄÄÚÈÝ

V1.0

2023-02-10

³õ´Î°ä²¼

  

0x05 ¸½Â¼

GA»Æ½ð¼×¼ò½é

GA»Æ½ð¼×³ÉÁ¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢Õ¼ÓÐÆëÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢°²È«¸ß¿Æ¼¼ÆóÒµ  ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢°²È«²úÆ·¡¢°²È«·þÎñ½â¾ö¹æ»®µÄÁ캽ÆóÒµÖ®Ò»  ¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°GA»Æ½ð¼×´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË  ¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊÓ×¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬Õ¼Óи²¸ÇÈ«¹úµÄÏúÊÛϵͳ¡¢Çþ·ϵͳºÍ¼¼ÊõÖ§³Öϵͳ  ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐÓ×°å¹ÒÅÆÉÏÊÐ  ¡££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬GA»Æ½ð¼×ÖÂÁ¦ÓÚÌṩӵÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´Ðµİ²È«²úÆ·ºÍ×î¼Ñʵ¼Ê·þÎñ£¬Ô®ÊÖ¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄ°²È«ÐԺͳö²úЧÁ¦£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢°²È«²úÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸ÖÂÁ¦  ¡£

 

¹ØÓÚGA»Æ½ð¼×

GA»Æ½ð¼×°²È«Ó¦¼±ÏìÓ¦ÖÐÐÄÖØÒªÕë¶Ô³ÁÒª°²È«·ì϶µÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвµý±¨ºÍ°²È«»ã±¨  ¡£

¹Ø×¢ÒÔϹ«¼ÒºÅ£¬»ñȡȫÇò×îа²È«×ÊѶ£º

image.png