CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:L/Au:N/C:C/I:C/A:C
AI Score
Confidence
Low
EPSS
Percentile
73.7%
The authorization implementation on Dahua DVR appliances accepts a hash string representing the current date for the role of a master password, which makes it easier for remote attackers to obtain administrative access and change the administrator password via requests involving (1) ActiveX, (2) a standalone client, or (3) unspecified other vectors, a different vulnerability than CVE-2013-3612.
Vendor | Product | Version | CPE |
---|---|---|---|
dahuasecurity | dvr0404hd-a | - | cpe:2.3:h:dahuasecurity:dvr0404hd-a:-:*:*:*:*:*:*:* |
dahuasecurity | dvr0404hd-l | - | cpe:2.3:h:dahuasecurity:dvr0404hd-l:-:*:*:*:*:*:*:* |
dahuasecurity | dvr0404hd-s | - | cpe:2.3:h:dahuasecurity:dvr0404hd-s:-:*:*:*:*:*:*:* |
dahuasecurity | dvr0404hd-u | - | cpe:2.3:h:dahuasecurity:dvr0404hd-u:-:*:*:*:*:*:*:* |
dahuasecurity | dvr0404hf-a-e | - | cpe:2.3:h:dahuasecurity:dvr0404hf-a-e:-:*:*:*:*:*:*:* |
dahuasecurity | dvr0404hf-al-e | - | cpe:2.3:h:dahuasecurity:dvr0404hf-al-e:-:*:*:*:*:*:*:* |
dahuasecurity | dvr0404hf-s-e | - | cpe:2.3:h:dahuasecurity:dvr0404hf-s-e:-:*:*:*:*:*:*:* |
dahuasecurity | dvr0404hf-u-e | - | cpe:2.3:h:dahuasecurity:dvr0404hf-u-e:-:*:*:*:*:*:*:* |
dahuasecurity | dvr0804 | - | cpe:2.3:h:dahuasecurity:dvr0804:-:*:*:*:*:*:*:* |
dahuasecurity | dvr0804hd-l | - | cpe:2.3:h:dahuasecurity:dvr0804hd-l:-:*:*:*:*:*:*:* |