9.8
CVSSv3

CVE-2017-9315

Published: 28/11/2017 Updated: 03/10/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Customer of Dahua IP camera or IP PTZ could submit relevant device information to receive a time limited temporary password from Dahua authorized dealer to reset the admin password. The algorithm used in this mechanism is potentially at risk of being compromised and subsequently utilized by attacker.

Vulnerable Product Search on Vulmon Subscribe to Product

dahuasecurity ipc-hfw1xxx_firmware -

dahuasecurity ipc-hdw1xxx_firmware -

dahuasecurity ipc-hdbw1xxx_firmware -

dahuasecurity ipc-hfw2xxx_firmware -

dahuasecurity ipc-hdw2xxx_firmware -

dahuasecurity ipc-hdbw2xxx_firmware -

dahuasecurity ipc-hfw4xxx_firmware -

dahuasecurity ipc-hdw4xxx_firmware -

dahuasecurity ipc-hdbw4xxx_firmware -

dahuasecurity ipc-hf5xxx_firmware -

dahuasecurity ipc-hfw5xxx_firmware -

dahuasecurity ipc-hdw5xxx_firmware -

dahuasecurity ipc-hdbw5xxx_firmware -

dahuasecurity ipc-hf8xxx_firmware -

dahuasecurity ipc-hfw8xxx_firmware -

dahuasecurity ipc-hdbw8xxx_firmware -

dahuasecurity ipc-ebw8xxx_firmware -

dahuasecurity ipc-pfw8xxx_firmware -

dahuasecurity dh-sd2xxxxx_firmware -

dahuasecurity ipc-pdbw8xxx_firmware -

dahuasecurity ipc-hum8xxx_firmware -

dahuasecurity psd8xxxx_firmware -

dahuasecurity dh-sd4xxxxx_firmware -

dahuasecurity dh-sd5xxxxx_firmware -

dahuasecurity dh-sd6xxxxx_firmware -