Lucene search

K
cve[email protected]CVE-2013-5754
HistoryOct 03, 2022 - 4:14 p.m.

CVE-2013-5754

2022-10-0316:14:54
CWE-264
web.nvd.nist.gov
23
dahua
dvr
appliances
authorization
vulnerability
cve-2013-5754
nvd
remote attackers
administrative access
hash string
master password
activex
standalone client
cve-2013-3612

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

6.8 Medium

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

70.7%

The authorization implementation on Dahua DVR appliances accepts a hash string representing the current date for the role of a master password, which makes it easier for remote attackers to obtain administrative access and change the administrator password via requests involving (1) ActiveX, (2) a standalone client, or (3) unspecified other vectors, a different vulnerability than CVE-2013-3612.

Affected configurations

NVD
Node
dahuasecuritydvr0404hd-aMatch-
OR
dahuasecuritydvr0404hd-lMatch-
OR
dahuasecuritydvr0404hd-sMatch-
OR
dahuasecuritydvr0404hd-uMatch-
OR
dahuasecuritydvr0404hf-a-eMatch-
OR
dahuasecuritydvr0404hf-al-eMatch-
OR
dahuasecuritydvr0404hf-s-eMatch-
OR
dahuasecuritydvr0404hf-u-eMatch-
OR
dahuasecuritydvr0804Match-
OR
dahuasecuritydvr0804hd-lMatch-
OR
dahuasecuritydvr0804hd-sMatch-
OR
dahuasecuritydvr0804hf-a-eMatch-
OR
dahuasecuritydvr0804hf-al-eMatch-
OR
dahuasecuritydvr0804hf-l-eMatch-
OR
dahuasecuritydvr0804hf-s-eMatch-
OR
dahuasecuritydvr0804hf-u-eMatch-
OR
dahuasecuritydvr1604hd-lMatch-
OR
dahuasecuritydvr1604hd-sMatch-
OR
dahuasecuritydvr1604hf-a-eMatch-
OR
dahuasecuritydvr1604hf-al-eMatch-
OR
dahuasecuritydvr1604hf-l-eMatch-
OR
dahuasecuritydvr1604hf-s-eMatch-
OR
dahuasecuritydvr1604hf-u-eMatch-
OR
dahuasecuritydvr2104cMatch-
OR
dahuasecuritydvr2104hMatch-
OR
dahuasecuritydvr2104hcMatch-
OR
dahuasecuritydvr2104heMatch-
OR
dahuasecuritydvr2108cMatch-
OR
dahuasecuritydvr2108hMatch-
OR
dahuasecuritydvr2108hcMatch-
OR
dahuasecuritydvr2108heMatch-
OR
dahuasecuritydvr2116cMatch-
OR
dahuasecuritydvr2116hMatch-
OR
dahuasecuritydvr2116hcMatch-
OR
dahuasecuritydvr2116heMatch-
OR
dahuasecuritydvr2404hf-sMatch-
OR
dahuasecuritydvr2404lf-alMatch-
OR
dahuasecuritydvr2404lf-sMatch-
OR
dahuasecuritydvr3204hf-sMatch-
OR
dahuasecuritydvr3204lf-alMatch-
OR
dahuasecuritydvr3204lf-sMatch-
OR
dahuasecuritydvr3224lMatch-
OR
dahuasecuritydvr3232lMatch-
OR
dahuasecuritydvr5104cMatch-
OR
dahuasecuritydvr5104hMatch-
OR
dahuasecuritydvr5104heMatch-
OR
dahuasecuritydvr5108cMatch-
OR
dahuasecuritydvr5108hMatch-
OR
dahuasecuritydvr5108heMatch-
OR
dahuasecuritydvr5116cMatch-
OR
dahuasecuritydvr5116hMatch-
OR
dahuasecuritydvr5116heMatch-
OR
dahuasecuritydvr5204aMatch-
OR
dahuasecuritydvr5204lMatch-
OR
dahuasecuritydvr5208aMatch-
OR
dahuasecuritydvr5208lMatch-
OR
dahuasecuritydvr5216aMatch-
OR
dahuasecuritydvr5216lMatch-
OR
dahuasecuritydvr5404Match-
OR
dahuasecuritydvr5408Match-
OR
dahuasecuritydvr5416Match-
OR
dahuasecuritydvr5804Match-
OR
dahuasecuritydvr5808Match-
OR
dahuasecuritydvr5816Match-
OR
dahuasecuritydvr6404lf-sMatch-

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

6.8 Medium

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

70.7%