7.5

CVE-2013-6117

Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive information including user credentials, change user passwords, clear log files, and perform other actions via a request to TCP port 37777.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DahuasecurityDvr Firmware Version2.608.0000.0
DahuasecurityDvr Firmware Version2.608.gv00.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 70.71% 0.993
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

http://blog.depthsecurity.com/2013/11/dahua-dvr-authentication-bypass-cve.html
http://packetstormsecurity.com/files/124022/Dahua-DVR-Authentication-Bypass.html
http://seclists.org/bugtraq/2013/Nov/62
http://www.exploit-db.com/exploits/29673
http://www.osvdb.org/99783