CVE & CISA-KEV Catalog

CVE-2024-39945

MEDIUM
4.9
CVSS v3
NVD

Description

A vulnerability has been found in Dahua products. After obtaining the administrator's username and password, the attacker can send a carefully crafted data packet to the interface with vulnerabilities, causing the device to crash.

How to fix

Remediation Available
nvr4104-4ks2\/l firmwareNVD
Affected:< 4.003.0000000.1.r.240515Fixed in:4.003.0000000.1.r.240515CVE-2024-39945derived from NVD
nvr4104-4ks3 firmwareNVD
Affected:< 4.003.0000000.0.r.240312Fixed in:4.003.0000000.0.r.240312CVE-2024-39945derived from NVD
nvr4104-p-4ks2\/l firmwareNVD
Affected:< 4.003.0000000.1.r.240515Fixed in:4.003.0000000.1.r.240515CVE-2024-39945derived from NVD
nvr4104-p-4ks3\(960g\) firmwareNVD
Affected:< 4.003.0000000.0.r.240312Fixed in:4.003.0000000.0.r.240312CVE-2024-39945derived from NVD
nvr4104-p-4ks3 firmwareNVD
Affected:< 4.003.0000000.0.r.240312Fixed in:4.003.0000000.0.r.240312CVE-2024-39945derived from NVD
nvr4104hs-4ks2\/l firmwareNVD
Affected:< 4.003.0000000.1.r.240515Fixed in:4.003.0000000.1.r.240515CVE-2024-39945derived from NVD
nvr4104hs-4ks3\(960g\) firmwareNVD
Affected:< 4.003.0000000.0.r.240312Fixed in:4.003.0000000.0.r.240312CVE-2024-39945derived from NVD
nvr4104hs-4ks3 firmwareNVD
Affected:< 4.003.0000000.0.r.240312Fixed in:4.003.0000000.0.r.240312CVE-2024-39945derived from NVD
nvr4104hs-p-4ks2\/l firmwareNVD
Affected:< 4.003.0000000.1.r.240515Fixed in:4.003.0000000.1.r.240515CVE-2024-39945derived from NVD
nvr4104hs-p-4ks3\(960g\) firmwareNVD
Affected:< 4.003.0000000.0.r.240312Fixed in:4.003.0000000.0.r.240312CVE-2024-39945derived from NVD
nvr4104hs-p-4ks3 firmwareNVD
Affected:< 4.003.0000000.0.r.240312Fixed in:4.003.0000000.0.r.240312CVE-2024-39945derived from NVD
nvr4108-4ks3 firmwareNVD
Affected:< 4.003.0000000.0.r.240312Fixed in:4.003.0000000.0.r.240312CVE-2024-39945derived from NVD
nvr4108-8p-4ks2\/l firmwareNVD
Affected:< 4.003.0000000.1.r.240515Fixed in:4.003.0000000.1.r.240515CVE-2024-39945derived from NVD
nvr4108-8p-4ks3 firmwareNVD
Affected:< 4.003.0000000.0.r.240312Fixed in:4.003.0000000.0.r.240312CVE-2024-39945derived from NVD
nvr4108-p-4ks2\/l firmwareNVD
Affected:< 4.003.0000000.1.r.240515Fixed in:4.003.0000000.1.r.240515CVE-2024-39945derived from NVD
nvr4108-p-4ks3 firmwareNVD
Affected:< 4.003.0000000.0.r.240312Fixed in:4.003.0000000.0.r.240312CVE-2024-39945derived from NVD
nvr4108hs-4ks2\/l firmwareNVD
Affected:< 4.003.0000000.1.r.240515Fixed in:4.003.0000000.1.r.240515CVE-2024-39945derived from NVD
nvr4108hs-4ks3\(960g\) firmwareNVD
Affected:< 4.003.0000000.0.r.240312Fixed in:4.003.0000000.0.r.240312CVE-2024-39945derived from NVD
nvr4108hs-4ks3 firmwareNVD
Affected:< 4.003.0000000.0.r.240312Fixed in:4.003.0000000.0.r.240312CVE-2024-39945derived from NVD
nvr4108hs-8p-4ks2\/l firmwareNVD
Affected:< 4.003.0000000.1.r.240515Fixed in:4.003.0000000.1.r.240515CVE-2024-39945derived from NVD
nvr4108hs-8p-4ks3 firmwareNVD
Affected:< 4.003.0000000.0.r.240312Fixed in:4.003.0000000.0.r.240312CVE-2024-39945derived from NVD
nvr4108hs-p-4ks2\/l firmwareNVD
Affected:< 4.003.0000000.1.r.240515Fixed in:4.003.0000000.1.r.240515CVE-2024-39945derived from NVD
nvr4108hs-p-4ks3 firmwareNVD
Affected:< 4.003.0000000.0.r.240312Fixed in:4.003.0000000.0.r.240312CVE-2024-39945derived from NVD
nvr4116-4ks2\/l firmwareNVD
Affected:< 4.003.0000000.1.r.240515Fixed in:4.003.0000000.1.r.240515CVE-2024-39945derived from NVD
nvr4116-4ks3 firmwareNVD
Affected:< 4.003.0000000.0.r.240312Fixed in:4.003.0000000.0.r.240312CVE-2024-39945derived from NVD
nvr4116-8p-4ks2\/l firmwareNVD
Affected:< 4.003.0000000.1.r.240515Fixed in:4.003.0000000.1.r.240515CVE-2024-39945derived from NVD
nvr4116-8p-4ks3 firmwareNVD
Affected:< 4.003.0000000.0.r.240312Fixed in:4.003.0000000.0.r.240312CVE-2024-39945derived from NVD
nvr4116hs-4ks2\/l firmwareNVD
Affected:< 4.003.0000000.1.r.240515Fixed in:4.003.0000000.1.r.240515CVE-2024-39945derived from NVD
nvr4116hs-4ks3 firmwareNVD
Affected:< 4.003.0000000.0.r.240312Fixed in:4.003.0000000.0.r.240312CVE-2024-39945derived from NVD
nvr4116hs-8p-4ks2\/l firmwareNVD
Affected:< 4.003.0000000.1.r.240515Fixed in:4.003.0000000.1.r.240515CVE-2024-39945derived from NVD
nvr4116hs-8p-4ks3 firmwareNVD
Affected:< 4.003.0000000.0.r.240312Fixed in:4.003.0000000.0.r.240312CVE-2024-39945derived from NVD
nvr4204-4ks2\/l firmwareNVD
Affected:< 4.003.0000000.1.r.240515Fixed in:4.003.0000000.1.r.240515CVE-2024-39945derived from NVD
nvr4204-4ks3 firmwareNVD
Affected:< 4.003.0000000.0.r.240312Fixed in:4.003.0000000.0.r.240312CVE-2024-39945derived from NVD
nvr4204-p-4ks2\/l firmwareNVD
Affected:< 4.003.0000000.1.r.240515Fixed in:4.003.0000000.1.r.240515CVE-2024-39945derived from NVD
nvr4204-p-4ks3 firmwareNVD
Affected:< 4.003.0000000.0.r.240312Fixed in:4.003.0000000.0.r.240312CVE-2024-39945derived from NVD
nvr4208-4ks2\/l firmwareNVD
Affected:< 4.003.0000000.1.r.240515Fixed in:4.003.0000000.1.r.240515CVE-2024-39945derived from NVD
nvr4208-4ks3 firmwareNVD
Affected:< 4.003.0000000.0.r.240312Fixed in:4.003.0000000.0.r.240312CVE-2024-39945derived from NVD
nvr4208-8p-4ks2\/l firmwareNVD
Affected:< 4.003.0000000.1.r.240515Fixed in:4.003.0000000.1.r.240515CVE-2024-39945derived from NVD
nvr4208-8p-4ks3 firmwareNVD
Affected:< 4.003.0000000.0.r.240312Fixed in:4.003.0000000.0.r.240312CVE-2024-39945derived from NVD
nvr4216-16p-4ks2\/l firmwareNVD
Affected:< 4.003.0000000.1.r.240515Fixed in:4.003.0000000.1.r.240515CVE-2024-39945derived from NVD
nvr4216-16p-4ks3 firmwareNVD
Affected:< 4.003.0000000.0.r.240312Fixed in:4.003.0000000.0.r.240312CVE-2024-39945derived from NVD
nvr4216-4ks2\/l firmwareNVD
Affected:< 4.003.0000000.1.r.240515Fixed in:4.003.0000000.1.r.240515CVE-2024-39945derived from NVD
nvr4216-4ks3 firmwareNVD
Affected:< 4.003.0000000.0.r.240312Fixed in:4.003.0000000.0.r.240312CVE-2024-39945derived from NVD
nvr4232-16p-4ks2\/l firmwareNVD
Affected:< 4.003.0000000.1.r.240515Fixed in:4.003.0000000.1.r.240515CVE-2024-39945derived from NVD
nvr4232-16p-4ks3 firmwareNVD
Affected:< 4.003.0000000.0.r.240312Fixed in:4.003.0000000.0.r.240312CVE-2024-39945derived from NVD
nvr4232-4ks2\/l firmwareNVD
Affected:< 4.003.0000000.1.r.240515Fixed in:4.003.0000000.1.r.240515CVE-2024-39945derived from NVD
nvr4232-4ks3 firmwareNVD
Affected:< 4.003.0000000.0.r.240312Fixed in:4.003.0000000.0.r.240312CVE-2024-39945derived from NVD
nvr4416-16p-4ks2\/i firmwareNVD
Affected:< 4.001.0000001.6.r.240725Fixed in:4.001.0000001.6.r.240725CVE-2024-39945derived from NVD
nvr4416-4ks2\/i firmwareNVD
Affected:< 4.001.0000001.6.r.240725Fixed in:4.001.0000001.6.r.240725CVE-2024-39945derived from NVD
nvr4432-16p-4ks2\/i firmwareNVD
Affected:< 4.001.0000001.6.r.240725Fixed in:4.001.0000001.6.r.240725CVE-2024-39945derived from NVD
nvr4432-4ks2\/i firmwareNVD
Affected:< 4.001.0000001.6.r.240725Fixed in:4.001.0000001.6.r.240725CVE-2024-39945derived from NVD
nvr4816-16p-4ks2\/i firmwareNVD
Affected:< 4.001.0000001.6.r.240725Fixed in:4.001.0000001.6.r.240725CVE-2024-39945derived from NVD
nvr4816-4ks2\/i firmwareNVD
Affected:< 4.001.0000001.6.r.240725Fixed in:4.001.0000001.6.r.240725CVE-2024-39945derived from NVD
nvr4832-16p-4ks2\/i firmwareNVD
Affected:< 4.001.0000001.6.r.240725Fixed in:4.001.0000001.6.r.240725CVE-2024-39945derived from NVD
nvr4832-4ks2\/i firmwareNVD
Affected:< 4.001.0000001.6.r.240725Fixed in:4.001.0000001.6.r.240725CVE-2024-39945derived from NVD

Remediation is compiled from vendor and distribution security advisories. Always confirm against the linked source for your exact version and platform.

CVSS v3 Vector

Exploitability

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredHigh
User InteractionNone
ScopeUnchanged

Impact

ConfidentialityNone
IntegrityNone
AvailabilityHigh

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

Exploit Intelligence

0.46%probability of exploitation in 30 days
36thpercentile

Low risk: more likely to be exploited than 36% of all known CVEs.

References

Vendor Advisory1
Embed a live status badge for CVE-2024-39945
CVE-2024-39945 severity badge

Markdown

[![CVE-2024-39945](https://tridentstack.com/cve/badge/CVE-2024-39945.svg)](https://tridentstack.com/cve/CVE-2024-39945)

HTML

<a href="https://tridentstack.com/cve/CVE-2024-39945"><img src="https://tridentstack.com/cve/badge/CVE-2024-39945.svg" alt="CVE-2024-39945"></a>

Find and fix vulnerabilities across your fleet

TridentStack Control continuously scans your Windows, macOS, and Linux fleet for known vulnerabilities, prioritizes them by severity and active exploitation, and patches them automatically.

Start free

This product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2025-03-27.