7.8

CVE-2013-3613

Dahua DVR appliances do not properly restrict UPnP requests, which makes it easier for remote attackers to obtain access via vectors involving a replay attack against the TELNET port.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DahuasecurityDvr0404hd-a Version-
DahuasecurityDvr0404hd-l Version-
DahuasecurityDvr0404hd-s Version-
DahuasecurityDvr0404hd-u Version-
DahuasecurityDvr0804 Version-
DahuasecurityDvr0804hd-l Version-
DahuasecurityDvr0804hd-s Version-
DahuasecurityDvr1604hd-l Version-
DahuasecurityDvr1604hd-s Version-
DahuasecurityDvr2104c Version-
DahuasecurityDvr2104h Version-
DahuasecurityDvr2104hc Version-
DahuasecurityDvr2104he Version-
DahuasecurityDvr2108c Version-
DahuasecurityDvr2108h Version-
DahuasecurityDvr2108hc Version-
DahuasecurityDvr2108he Version-
DahuasecurityDvr2116c Version-
DahuasecurityDvr2116h Version-
DahuasecurityDvr2116hc Version-
DahuasecurityDvr2116he Version-
DahuasecurityDvr2404hf-s Version-
DahuasecurityDvr2404lf-s Version-
DahuasecurityDvr3204hf-s Version-
DahuasecurityDvr3204lf-s Version-
DahuasecurityDvr3224l Version-
DahuasecurityDvr3232l Version-
DahuasecurityDvr5104c Version-
DahuasecurityDvr5104h Version-
DahuasecurityDvr5104he Version-
DahuasecurityDvr5108c Version-
DahuasecurityDvr5108h Version-
DahuasecurityDvr5108he Version-
DahuasecurityDvr5116c Version-
DahuasecurityDvr5116h Version-
DahuasecurityDvr5116he Version-
DahuasecurityDvr5204a Version-
DahuasecurityDvr5204l Version-
DahuasecurityDvr5208a Version-
DahuasecurityDvr5208l Version-
DahuasecurityDvr5216a Version-
DahuasecurityDvr5216l Version-
DahuasecurityDvr5404 Version-
DahuasecurityDvr5408 Version-
DahuasecurityDvr5416 Version-
DahuasecurityDvr5804 Version-
DahuasecurityDvr5808 Version-
DahuasecurityDvr5816 Version-
DahuasecurityDvr6404lf-s Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 8.49% 0.92
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 10 6.9
AV:N/AC:L/Au:N/C:C/I:N/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.