7.5
CVSSv2

CVE-2013-6117

Published: 11/07/2014 Updated: 14/07/2014
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 756
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote malicious users to bypass authentication and obtain sensitive information including user credentials, change user passwords, clear log files, and perform other actions via a request to TCP port 37777.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dahuasecurity dvr firmware 2.608.0000.0

dahuasecurity dvr firmware 2.608.gv00.0

Exploits

Dahua DVR Authentication Bypass - CVE-2013-6117 --Summary-- Dahua web-enabled DVRs and rebranded versions do not enforce authentication on their administrative services # Zhejiang Dahua Technology Co, Ltd # wwwdahuasecuritycom --Affects-- # Dahua web-enabled DVRs # Dahua-rebranded web-enabled DVRs # Verified on v260800000 and 2 ...

Github Repositories

CVE-2013-6117

CVE-2013-6117 $ /CVE-2013-6117 -h Options: -h, --help display help information -f, --filename File containing list of IP addresses -t, --target Target IP -n, --threads No of concurrent threads (default: 100) $ /CVE-2013-6117 -f hostfiletxt 1244|nameno-iporg:80|username|password

IoT Security Reading List

Malware This is a reading list for those interested in studying Malware If you have any suggestions, please send a pull request Linux Malware 2019, IEEE S&P, LBM: A Security Framework for Peripherals within the Linux Kernel 2018, IEEE S&P, Understanding Linux Malware 2018, Class 9: Adversarial Malware Detection 2017, USENIX Security, Understanding the Mirai B