5.8
CVSSv2

CVE-2017-9316

Published: 27/11/2017 Updated: 20/12/2017
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 4.2 | Exploitability Score: 2.2
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P

Vulnerability Summary

Firmware upgrade authentication bypass vulnerability was found in Dahua IPC-HDW4300S and some IP products. The vulnerability was caused by internal Debug function. This particular function was used for problem analysis and performance tuning during product development phase. It allowed the device to receive only specific data (one direction, no transmit) and therefore it was not involved in any instance of collecting user privacy data or allowing remote code execution.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dahuasecurity nvr11hs_firmware 3.210.0000.2.r.20150715

dahuasecurity nvr11hs_firmware 3.210.0000.3.r.20150921

dahuasecurity nvr11hs_firmware 3.210.0000.5.r.20160409

dahuasecurity nvr11hs_firmware 3.210.0000.5.r.20160603

dahuasecurity nvr11hs_firmware 3.210.0000.0.r.20150206

dahuasecurity nvr11hs_firmware 3.210.0000.5.r.20161226

dahuasecurity nvr11hs_firmware 3.210.0000.5.r.20170321

dahuasecurity nvr11hs_firmware 3.210.0000.1.r.20150420

dahuasecurity nvr11hs_firmware 3.210.0000.5.r.20160803

dahuasecurity nvr11hs_firmware 3.210.0000.5.r.20170305

dahuasecurity ipc-hdw4300s_firmware 2.420.0005.0.r.20141205

dahuasecurity ipc-hdw4300s_firmware 2.420.0006.0.r.20150311

dahuasecurity ipc-hdw4300s_firmware 2.420.0007.0.r.20150409

dahuasecurity ipc-hdw4300s_firmware 2.420.0008.0.r.20150710

dahuasecurity ipc-hdw4300s_firmware 2.240.0009.0.r.20131015

dahuasecurity ipc-hdw4300s_firmware 2.420.0000.0.r.20140419

dahuasecurity ipc-hdw4300s_firmware 2.420.0002.0.r.20140724

dahuasecurity ipc-hdw4300s_firmware 2.400.0000.0.r.20131231

dahuasecurity ipc-hdw4300s_firmware 2.420.0002.0.r.20140621

dahuasecurity ipc-hfw4x00_firmware 2.400.0000.3.r.20150312

dahuasecurity ipc-hfw4x00_firmware 2.420.0006.0.r.20150311

dahuasecurity ipc-hdw4x00_firmware 2.420.0006.0.r.20150311

dahuasecurity ipc-hdw4x00_firmware 2.400.0000.3.r.20150312

dahuasecurity ipc-hdbw4x00_firmware 2.400.0000.3.r.20150312

dahuasecurity ipc-hdbw4x00_firmware 2.420.0006.0.r.20150311

dahuasecurity ipc-hf5x00_firmware 2.400.0000.3.r.20150312

dahuasecurity ipc-hf5x00_firmware 2.420.0006.0.r.20150311

dahuasecurity ipc-hfw5x00_firmware 2.420.0006.0.r.20150311

dahuasecurity ipc-hfw5x00_firmware 2.400.0000.3.r.20150312

dahuasecurity ipc-hdw5x00_firmware 2.400.0000.3.r.20150312

dahuasecurity ipc-hdw5x00_firmware 2.420.0006.0.r.20150311

dahuasecurity ipc-hdbw5x00_firmware 2.420.0006.0.r.20150311

dahuasecurity ipc-hdbw5x00_firmware 2.400.0000.3.r.20150312