10
CVSSv2

CVE-2013-3612

Published: 17/09/2013 Updated: 17/09/2013
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Dahua DVR appliances have a hardcoded password for (1) the root account and (2) an unspecified "backdoor" account, which makes it easier for remote malicious users to obtain administrative access via authorization requests involving (a) ActiveX, (b) a standalone client, or (c) unknown other vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

dahuasecurity dvr0404hd-s -

dahuasecurity dvr0404hd-l -

dahuasecurity dvr1604hd-l -

dahuasecurity dvr3204hf-s -

dahuasecurity dvr3204lf-al -

dahuasecurity dvr1604hf-a-e -

dahuasecurity dvr5408 -

dahuasecurity dvr1604hf-al-e -

dahuasecurity dvr5808 -

dahuasecurity dvr5216a -

dahuasecurity dvr5108h -

dahuasecurity dvr2116h -

dahuasecurity dvr5108he -

dahuasecurity dvr2116he -

dahuasecurity dvr2108hc -

dahuasecurity dvr6404lf-s -

dahuasecurity dvr2404hf-s -

dahuasecurity dvr0404hf-u-e -

dahuasecurity dvr0804hf-u-e -

dahuasecurity dvr1604hf-l-e -

dahuasecurity dvr0804hf-l-e -

dahuasecurity dvr0404hf-a-e -

dahuasecurity dvr0804hf-a-e -

dahuasecurity dvr5204l -

dahuasecurity dvr5208l -

dahuasecurity dvr5216l -

dahuasecurity dvr5204a -

dahuasecurity dvr5104c -

dahuasecurity dvr5108c -

dahuasecurity dvr5116c -

dahuasecurity dvr2104he -

dahuasecurity dvr2108he -

dahuasecurity dvr3232l -

dahuasecurity dvr2404lf-s -

dahuasecurity dvr3204lf-s -

dahuasecurity dvr0804hd-s -

dahuasecurity dvr0404hf-s-e -

dahuasecurity dvr0804hf-s-e -

dahuasecurity dvr1604hf-s-e -

dahuasecurity dvr0404hf-al-e -

dahuasecurity dvr0804hf-al-e -

dahuasecurity dvr5116h -

dahuasecurity dvr0404hd-a -

dahuasecurity dvr2104h -

dahuasecurity dvr2108h -

dahuasecurity dvr2104c -

dahuasecurity dvr2108c -

dahuasecurity dvr2116c -

dahuasecurity dvr0404hd-u -

dahuasecurity dvr0804 -

dahuasecurity dvr1604hf-u-e -

dahuasecurity dvr0804hd-l -

dahuasecurity dvr3224l -

dahuasecurity dvr1604hd-s -

dahuasecurity dvr2404lf-al -

dahuasecurity dvr5404 -

dahuasecurity dvr5416 -

dahuasecurity dvr5804 -

dahuasecurity dvr5816 -

dahuasecurity dvr5208a -

dahuasecurity dvr5104h -

dahuasecurity dvr5104he -

dahuasecurity dvr5116he -

dahuasecurity dvr2104hc -

dahuasecurity dvr2116hc -

Exploits

Dahua DVR Authentication Bypass - CVE-2013-6117 --Summary-- Dahua web-enabled DVRs and rebranded versions do not enforce authentication on their administrative services # Zhejiang Dahua Technology Co, Ltd # wwwdahuasecuritycom --Affects-- # Dahua web-enabled DVRs # Dahua-rebranded web-enabled DVRs # Verified on v260800000 and 2 ...