Dahuasecurity.com uses cookies and similar technologies. Dahua uses functional cookies to ensure that its websites operate properly and analytical cookies to make your user experience optimal. Third-party cookies may collect data outside our websites as well. By clicking on " Agree" or by continuing to use this website, you give consent for the setting of cookies and the processing of personal data involved. More information on our cookie statement.

Vulnerability Response Process

258

Vulnerability Reporting and Response Process:


Dahua PSIRT strictly controls the circulation of reported information on a need to know basis. We also request researcher to keep information about any vulnerabilities discovered confidential until it is publicly disclosed.



Dahua PSIRT releases two kinds of security bulletin:

SA (Security Advisory): Provide relevant verified technical information, including but not limited to the mitigation measure and solutions.
SN (Security Notice): Provide key information related to the subject of notice, when a potential vulnerability is reported but not yet verified.

Dahua PSIRT adopts CVSSv3 standard (https://www.first.org/cvss/specification-document) to assess a vulnerability on Base Score and Temporal Score. Customer could calculate the Environmental Score according to their own environment if necessary.

Dahua make reference to vulnerability disclosed in other media or information sources using CVE(Common Vulnerability and Exposures) and CNCVE. Dahua PSIRT releases two kinds of security bulletin whenever necessary, including SN (Security Notice) and SA (Security Advisory).