8.8

CVE-2017-9317

Privilege escalation vulnerability found in some Dahua IP devices. Attacker in possession of low privilege account can gain access to credential information of high privilege account and further obtain device information or attack the device.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DahuasecurityXvr5x16 Firmware Version < 3.218.0000002.1.r.171229
   DahuasecurityXvr5x16 Version-
DahuasecurityXvr5x08 Firmware Version < 3.218.0000002.1.r.171229
   DahuasecurityXvr5x08 Version-
DahuasecurityXvr5x04 Firmware Version < 3.218.0000002.1.r.171229
   DahuasecurityXvr5x04 Version-
DahuasecurityXvr7x16 Firmware Version < 3.218.0000002.1.r.171229
   DahuasecurityXvr7x16 Version-
DahuasecurityIpc-hdbw4xxx Firmware Version < 2.622.0000000.18.r.20171110
   DahuasecurityIpc-hdbw4xxx Version-
DahuasecurityIpc-hdbw4xxx Firmware Version < 2.621.0000.28.r.20170912
   DahuasecurityIpc-hdbw4xxx Version-
DahuasecurityIpc-hdbw5xxx Firmware Version < 2.622.0000000.18.r.20171110
   DahuasecurityIpc-hdbw5xxx Version-
DahuasecurityIpc-hdbw5xxx Firmware Version < 2.621.0000.28.r.20170912
   DahuasecurityIpc-hdbw5xxx Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.37% 0.583
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.