CVE-2023-3121
Dahua Smart Parking Management image server-side request forgery
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
A vulnerability has been found in Dahua Smart Parking Management up to 20230528 and classified as problematic. This vulnerability affects unknown code of the file /ipms/imageConvert/image. The manipulation of the argument fileUrl leads to server-side request forgery. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-230800. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Se ha encontrado una vulnerabilidad en Dahua Smart Parking Management hasta 20230528 y se ha clasificado como problemática. Esta vulnerabilidad afecta a código desconocido del archivo "/ipms/imageConvert/image". La manipulación del argumento "fileUrl" conduce a la falsificación de peticiones del lado del servidor. El exploit ha sido revelado al público y puede ser utilizado. El identificador de esta vulnerabilidad es VDB-230800. NOTA: Se contactó con el proveedor en una fase temprana acerca de esta divulgación, pero no respondió de ninguna manera.
In Dahua Smart Parking Management bis 20230528 wurde eine problematische Schwachstelle gefunden. Es geht um eine nicht näher bekannte Funktion der Datei /ipms/imageConvert/image. Durch das Beeinflussen des Arguments fileUrl mit unbekannten Daten kann eine server-side request forgery-Schwachstelle ausgenutzt werden. Der Exploit steht zur öffentlichen Verfügung.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-06-06 CVE Reserved
- 2023-06-06 CVE Published
- 2024-08-02 CVE Updated
- 2024-08-02 First Exploit
- 2024-12-27 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-918: Server-Side Request Forgery (SSRF)
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://vuldb.com/?id.230800 | Technical Description |
URL | Date | SRC |
---|---|---|
https://github.com/RCEraser/cve/blob/main/DaHua..md | 2024-08-02 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Dahuasecurity Search vendor "Dahuasecurity" | Smart Parking Management Search vendor "Dahuasecurity" for product "Smart Parking Management" | <= 2023-05-28 Search vendor "Dahuasecurity" for product "Smart Parking Management" and version " <= 2023-05-28" | - |
Affected
|