6.5
CVSSv3

CVE-2017-9316

Published: 27/11/2017 Updated: 20/12/2017
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 4.2 | Exploitability Score: 2.2
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P

Vulnerability Summary

Firmware upgrade authentication bypass vulnerability was found in Dahua IPC-HDW4300S and some IP products. The vulnerability was caused by internal Debug function. This particular function was used for problem analysis and performance tuning during product development phase. It allowed the device to receive only specific data (one direction, no transmit) and therefore it was not involved in any instance of collecting user privacy data or allowing remote code execution.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dahuasecurity nvr11hs firmware 3.210.0000.0.r.20150206

dahuasecurity nvr11hs firmware 3.210.0000.1.r.20150420

dahuasecurity nvr11hs firmware 3.210.0000.2.r.20150715

dahuasecurity nvr11hs firmware 3.210.0000.3.r.20150921

dahuasecurity nvr11hs firmware 3.210.0000.5.r.20160409

dahuasecurity nvr11hs firmware 3.210.0000.5.r.20160603

dahuasecurity nvr11hs firmware 3.210.0000.5.r.20160803

dahuasecurity nvr11hs firmware 3.210.0000.5.r.20161226

dahuasecurity nvr11hs firmware 3.210.0000.5.r.20170305

dahuasecurity nvr11hs firmware 3.210.0000.5.r.20170321

dahuasecurity ipc-hdw4300s firmware 2.240.0009.0.r.20131015

dahuasecurity ipc-hdw4300s firmware 2.400.0000.0.r.20131231

dahuasecurity ipc-hdw4300s firmware 2.420.0000.0.r.20140419

dahuasecurity ipc-hdw4300s firmware 2.420.0002.0.r.20140621

dahuasecurity ipc-hdw4300s firmware 2.420.0002.0.r.20140724

dahuasecurity ipc-hdw4300s firmware 2.420.0005.0.r.20141205

dahuasecurity ipc-hdw4300s firmware 2.420.0006.0.r.20150311

dahuasecurity ipc-hdw4300s firmware 2.420.0007.0.r.20150409

dahuasecurity ipc-hdw4300s firmware 2.420.0008.0.r.20150710

dahuasecurity ipc-hfw4x00 firmware 2.400.0000.3.r.20150312

dahuasecurity ipc-hfw4x00 firmware 2.420.0006.0.r.20150311

dahuasecurity ipc-hdw4x00 firmware 2.400.0000.3.r.20150312

dahuasecurity ipc-hdw4x00 firmware 2.420.0006.0.r.20150311

dahuasecurity ipc-hdbw4x00 firmware 2.400.0000.3.r.20150312

dahuasecurity ipc-hdbw4x00 firmware 2.420.0006.0.r.20150311

dahuasecurity ipc-hf5x00 firmware 2.400.0000.3.r.20150312

dahuasecurity ipc-hf5x00 firmware 2.420.0006.0.r.20150311

dahuasecurity ipc-hfw5x00 firmware 2.400.0000.3.r.20150312

dahuasecurity ipc-hfw5x00 firmware 2.420.0006.0.r.20150311

dahuasecurity ipc-hdw5x00 firmware 2.400.0000.3.r.20150312

dahuasecurity ipc-hdw5x00 firmware 2.420.0006.0.r.20150311

dahuasecurity ipc-hdbw5x00 firmware 2.400.0000.3.r.20150312

dahuasecurity ipc-hdbw5x00 firmware 2.420.0006.0.r.20150311