7.5

CVE-2017-7927

A Use of Password Hash Instead of Password for Authentication issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX, DH-IPC-HFW1XXX, DH-IPC-HFW2XXX, DH-IPC-HFW4XXX, DH-SD6CXX, DH-NVR1XXX, DH-HCVR4XXX, DH-HCVR5XXX, DHI-HCVR51A04HE-S3, DHI-HCVR51A08HE-S3, and DHI-HCVR58A32S-S2 devices. The use of password hash instead of password for authentication vulnerability was identified, which could allow a malicious user to bypass authentication without obtaining the actual password.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dahuasecurity ≫ Dh-sd6cxx Firmware Version -
   Dahuasecurity ≫ Dh-sd6cxx Version -
Dahuasecurity ≫ Dh-nvr1xxx Firmware Version -
   Dahuasecurity ≫ Dh-nvr1xxx Version -
Dahuasecurity ≫ Dh-hcvr4xxx Firmware Version -
   Dahuasecurity ≫ Ddh-hcvr4xxx Version -
Dahuasecurity ≫ Dh-hcvr5xxx Firmware Version -
   Dahuasecurity ≫ Dh-hcvr5xxx Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 36.75% 0.983
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.3 3.9 3.4
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-798 Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

CWE-836 Use of Password Hash Instead of Password for Authentication

The product records password hashes in a data store, receives a hash of a password from a client, and compares the supplied hash to the hash obtained from the data store.

http://us.dahuasecurity.com/en/us/Security-Bulletin_030617.php
Patch
Vendor Advisory
http://www.securityfocus.com/bid/98312
Third Party Advisory
VDB Entry
https://ics-cert.us-cert.gov/advisories/ICSA-17-124-02
Third Party Advisory
US Government Resource
Mitigation