Lucene search

K
cve[email protected]CVE-2017-9315
HistoryNov 28, 2017 - 7:29 p.m.

CVE-2017-9315

2017-11-2819:29:00
web.nvd.nist.gov
33
dahua
ip camera
ip ptz
temporary password
compromised algorithm
security risk
nvd
cve-2017-9315

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.3 High

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

78.6%

Customer of Dahua IP camera or IP PTZ could submit relevant device information to receive a time limited temporary password from Dahua authorized dealer to reset the admin password. The algorithm used in this mechanism is potentially at risk of being compromised and subsequently utilized by attacker.

Affected configurations

NVD
Node
dahuasecurityipc-hfw1xxx_firmwareMatch-
AND
dahuasecurityipc-hfw1xxxMatch-
Node
dahuasecurityipc-hdw1xxx_firmwareMatch-
AND
dahuasecurityipc-hdw1xxxMatch-
Node
dahuasecurityipc-hdbw1xxx_firmwareMatch-
AND
dahuasecurityipc-hdbw1xxxMatch-
Node
dahuasecurityipc-hfw2xxx_firmwareMatch-
AND
dahuasecurityipc-hfw2xxxMatch-
Node
dahuasecurityipc-hdw2xxx_firmwareMatch-
AND
dahuasecurityipc-hdw2xxxMatch-
Node
dahuasecurityipc-hdbw2xxx_firmwareMatch-
AND
dahuasecurityipc-hdbw2xxxMatch-
Node
dahuasecurityipc-hfw4xxx_firmwareMatch-
AND
dahuasecurityipc-hfw4xxxMatch-
Node
dahuasecurityipc-hdw4xxx_firmwareMatch-
AND
dahuasecurityipc-hdw4xxxMatch-
Node
dahuasecurityipc-hdbw4xxx_firmwareMatch-
AND
dahuasecurityipc-hdbw4xxxMatch-
Node
dahuasecurityipc-hf5xxx_firmwareMatch-
AND
dahuasecurityipc-hf5xxxMatch-
Node
dahuasecurityipc-hfw5xxx_firmwareMatch-
AND
dahuasecurityipc-hfw5xxxMatch-
Node
dahuasecurityipc-hdw5xxx_firmwareMatch-
AND
dahuasecurityipc-hdw5xxxMatch-
Node
dahuasecurityipc-hdbw5xxx_firmwareMatch-
AND
dahuasecurityipc-hdbw5xxxMatch-
Node
dahuasecurityipc-hf8xxx_firmwareMatch-
AND
dahuasecurityipc-hf8xxxMatch-
Node
dahuasecurityipc-hfw8xxx_firmwareMatch-
AND
dahuasecurityipc-hfw8xxxMatch-
Node
dahuasecurityipc-hdbw8xxx_firmwareMatch-
AND
dahuasecurityipc-hdbw8xxxMatch-
Node
dahuasecurityipc-ebw8xxx_firmwareMatch-
AND
dahuasecurityipc-ebw8xxxMatch-
Node
dahuasecurityipc-pfw8xxx_firmwareMatch-
AND
dahuasecurityipc-pfw8xxxMatch-
Node
dahuasecuritydh-sd2xxxxx_firmwareMatch-
AND
dahuasecuritydh-sd2xxxxxMatch-
Node
dahuasecurityipc-pdbw8xxx_firmwareMatch-
AND
dahuasecurityipc-pdbw8xxxMatch-
Node
dahuasecurityipc-hum8xxx_firmwareMatch-
AND
dahuasecurityipc-hum8xxxMatch-
Node
dahuasecuritypsd8xxxx_firmwareMatch-
AND
dahuasecuritypsd8xxxxMatch-
Node
dahuasecuritydh-sd4xxxxx_firmwareMatch-
AND
dahuasecuritydh-sd4xxxxxMatch-
Node
dahuasecuritydh-sd5xxxxx_firmwareMatch-
AND
dahuasecuritydh-sd5xxxxxMatch-
Node
dahuasecuritydh-sd6xxxxx_firmwareMatch-
AND
dahuasecuritydh-sd6xxxxxMatch-

CNA Affected

[
  {
    "product": "Dahua IP Camera and IP PTZ IPC-HFW1XXX, IPC-HDW1XXX, IPC-HDBW1XXX, IPC-HFW2XXX, IPC-HDW2XXX, IPC-HDBW2XXX, IPC-HFW4XXX, IPC-HDW4XXX, IPC-HDBW4XXX, IPC-HF5XXX, IPC-HFW5XXX, IPC-HDW5XXX, IPC-HDBW5XXX, IPC-HF8XXX, IPC-HFW8XXX, IPC-HDBW8XXX, IPC-EBW8XXX, IPC-PFW8xxx, IPC-PDBW8xxx, IPC-HUM8xxx, PSD8xxxx, DH-SD2XXXXX, DH-SD4XXXXX, DH-SD5XXXXX, DH-SD6XXXXX",
    "vendor": "Dahua Technologies",
    "versions": [
      {
        "status": "affected",
        "version": "Versions Build between 2015/07 and 2017/03"
      }
    ]
  }
]

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.3 High

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

78.6%

Related for CVE-2017-9315