ID

VAR-201705-3743


CVE

CVE-2017-7925


TITLE

plural Dahua Vulnerabilities related to authorization, authority, and access control in products

Trust: 0.8

sources: JVNDB: JVNDB-2017-003971

DESCRIPTION

A Password in Configuration File issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX, DH-IPC-HFW1XXX, DH-IPC-HFW2XXX, DH-IPC-HFW4XXX, DH-SD6CXX, DH-NVR1XXX, DH-HCVR4XXX, DH-HCVR5XXX, DHI-HCVR51A04HE-S3, DHI-HCVR51A08HE-S3, and DHI-HCVR58A32S-S2 devices. The password in configuration file vulnerability was identified, which could lead to a malicious user assuming the identity of a privileged user and gaining access to sensitive information. plural Dahua The product contains vulnerabilities related to authorization, permissions, and access control.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Dahua DH-IPC-HDBW23A0RN-ZS is a camera product of Dahua Company of China. Dahua Technology is prone to an authentication-bypass vulnerability and an information-disclosure vulnerability. Attackers may exploit these issues to gain unauthorized access to restricted content by bypassing intended security restrictions or to obtain sensitive information that may aid in launching further attacks. Dahua DH-IPC-HDBW23A0RN-ZS, etc. There are security vulnerabilities in many Dahua products. The following products are affected: Dahua DH-IPC-HDBW23A0RN-ZS; DH-IPC-HDBW13A0SN; DH-IPC-HDW1XXX; DH-IPC-HDW2XXX; DH-IPC-HDW4XXX; DH-IPC-HFW4XXX; DH-SD6CXX; DH-NVR1XXX; DH-HCVR4XXX; DH-HCVR5XXX; DHI-HCVR51A04HE-S3; DHI-HCVR51A08HE-S3;

Trust: 2.7

sources: NVD: CVE-2017-7925 // JVNDB: JVNDB-2017-003971 // CNVD: CNVD-2017-08192 // BID: 98312 // IVD: b9a8ca3d-8ac9-429c-880c-4cc25c09c01b // VULHUB: VHN-116128

IOT TAXONOMY

category:['IoT', 'ICS', 'Network device']sub_category: -

Trust: 0.6

category:['ICS']sub_category: -

Trust: 0.2

sources: IVD: b9a8ca3d-8ac9-429c-880c-4cc25c09c01b // CNVD: CNVD-2017-08192

AFFECTED PRODUCTS

vendor:dahuasecuritymodel:dh-sd6cxxscope:eqversion: -

Trust: 1.6

vendor:dahuasecuritymodel:dhi-hcvr58a32s-s2scope:eqversion: -

Trust: 1.6

vendor:dahuasecuritymodel:dhi-hcvr51a08he-s3scope:eqversion: -

Trust: 1.6

vendor:dahuasecuritymodel:dh-ipc-hdbw23a0rn-zsscope:eqversion: -

Trust: 1.6

vendor:dahuasecuritymodel:dh-nvr1xxxscope:eqversion: -

Trust: 1.6

vendor:dahuasecuritymodel:dh-hcvr4xxxscope:eqversion: -

Trust: 1.6

vendor:dahuasecuritymodel:dh-ipc-hfw4xxxscope:eqversion: -

Trust: 1.6

vendor:dahuasecuritymodel:dhi-hcvr51a04he-s3scope:eqversion: -

Trust: 1.6

vendor:dahuasecuritymodel:dh-ipc-hfw2xxxscope:eqversion: -

Trust: 1.6

vendor:dahuasecuritymodel:dh-hcvr5xxxscope:eqversion: -

Trust: 1.6

vendor:dahuamodel:dh-ipc-hdbw23a0rn-zsscope: - version: -

Trust: 1.4

vendor:dahuamodel:dh-ipc-hdbw13a0snscope: - version: -

Trust: 1.4

vendor:dahuamodel:dh-ipc-hdw1xxxscope: - version: -

Trust: 1.4

vendor:dahuamodel:dh-ipc-hdw2xxxscope: - version: -

Trust: 1.4

vendor:dahuamodel:dh-ipc-hdw4xxxscope: - version: -

Trust: 1.4

vendor:dahuamodel:dh-ipc-hfw1xxxscope: - version: -

Trust: 1.4

vendor:dahuamodel:dh-ipc-hfw2xxxscope: - version: -

Trust: 1.4

vendor:dahuamodel:dh-ipc-hfw4xxxscope: - version: -

Trust: 1.4

vendor:dahuamodel:dh-sd6cxxscope: - version: -

Trust: 1.4

vendor:dahuamodel:dh-nvr1xxxscope: - version: -

Trust: 1.4

vendor:dahuamodel:dh-hcvr4xxxscope: - version: -

Trust: 1.4

vendor:dahuamodel:dh-hcvr5xxxscope: - version: -

Trust: 1.4

vendor:dahuamodel:dhi-hcvr51a04he-s3scope: - version: -

Trust: 1.4

vendor:dahuamodel:dhi-hcvr51a08he-s3scope: - version: -

Trust: 1.4

vendor:dahuamodel:dhi-hcvr58a32s-s2scope: - version: -

Trust: 1.4

vendor:dahuasecuritymodel:dh-ipc-hdbw13a0snscope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dh-ipc-hdw1xxxscope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dh-ipc-hdw4xxxscope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dh-ipc-hfw1xxxscope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dh-ipc-hdw2xxxscope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dhi-hcvr58a32s-s2scope:eqversion:0

Trust: 0.3

vendor:dahuasecuritymodel:dhi-hcvr51a08he-s3scope:eqversion:0

Trust: 0.3

vendor:dahuasecuritymodel:dhi-hcvr51a04he-s3scope:eqversion:0

Trust: 0.3

vendor:dahuasecuritymodel:dh-sd6cxxscope:eqversion:0

Trust: 0.3

vendor:dahuasecuritymodel:dh-nvr1xxxscope:eqversion:0

Trust: 0.3

vendor:dahuasecuritymodel:dh-ipc-hfw4xxxscope:eqversion:0

Trust: 0.3

vendor:dahuasecuritymodel:dh-ipc-hfw2xxxscope:eqversion:0

Trust: 0.3

vendor:dahuasecuritymodel:dh-ipc-hfw1xxxscope:eqversion:0

Trust: 0.3

vendor:dahuasecuritymodel:dh-ipc-hdw4xxxscope:eqversion:0

Trust: 0.3

vendor:dahuasecuritymodel:dh-ipc-hdw2xxxscope:eqversion:0

Trust: 0.3

vendor:dahuasecuritymodel:dh-ipc-hdw1xxxscope:eqversion:0

Trust: 0.3

vendor:dahuasecuritymodel:dh-ipc-hdbw23a0rn-zsscope:eqversion:0

Trust: 0.3

vendor:dahuasecuritymodel:dh-ipc-hdbw13a0snscope:eqversion:0

Trust: 0.3

vendor:dahuasecuritymodel:dh-hcvr5xxxscope:eqversion:0

Trust: 0.3

vendor:dahuasecuritymodel:dh-hcvr4xxxscope:eqversion:0

Trust: 0.3

vendor:dh ipc hdbw23a0rn zsmodel: - scope:eqversion: -

Trust: 0.2

vendor:dh nvr1xxxmodel: - scope:eqversion: -

Trust: 0.2

vendor:dh hcvr4xxxmodel: - scope:eqversion: -

Trust: 0.2

vendor:dh hcvr5xxxmodel: - scope:eqversion: -

Trust: 0.2

vendor:dhi hcvr51a04he s3model: - scope:eqversion: -

Trust: 0.2

vendor:dhi hcvr51a08he s3model: - scope:eqversion: -

Trust: 0.2

vendor:dhi hcvr58a32s s2model: - scope:eqversion: -

Trust: 0.2

vendor:dh ipc hdbw13a0snmodel: - scope:eqversion: -

Trust: 0.2

vendor:dh ipc hdw1xxxmodel: - scope:eqversion: -

Trust: 0.2

vendor:dh ipc hdw2xxxmodel: - scope:eqversion: -

Trust: 0.2

vendor:dh ipc hdw4xxxmodel: - scope:eqversion: -

Trust: 0.2

vendor:dh ipc hfw1xxxmodel: - scope:eqversion: -

Trust: 0.2

vendor:dh ipc hfw2xxxmodel: - scope:eqversion: -

Trust: 0.2

vendor:dh ipc hfw4xxxmodel: - scope:eqversion: -

Trust: 0.2

vendor:dh sd6cxxmodel: - scope:eqversion: -

Trust: 0.2

sources: IVD: b9a8ca3d-8ac9-429c-880c-4cc25c09c01b // CNVD: CNVD-2017-08192 // BID: 98312 // JVNDB: JVNDB-2017-003971 // CNNVD: CNNVD-201704-1045 // NVD: CVE-2017-7925

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-7925
value: CRITICAL

Trust: 1.0

NVD: CVE-2017-7925
value: CRITICAL

Trust: 0.8

CNVD: CNVD-2017-08192
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201704-1045
value: CRITICAL

Trust: 0.6

IVD: b9a8ca3d-8ac9-429c-880c-4cc25c09c01b
value: CRITICAL

Trust: 0.2

VULHUB: VHN-116128
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2017-7925
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2017-08192
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: b9a8ca3d-8ac9-429c-880c-4cc25c09c01b
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

VULHUB: VHN-116128
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-7925
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: IVD: b9a8ca3d-8ac9-429c-880c-4cc25c09c01b // CNVD: CNVD-2017-08192 // VULHUB: VHN-116128 // JVNDB: JVNDB-2017-003971 // CNNVD: CNNVD-201704-1045 // NVD: CVE-2017-7925

PROBLEMTYPE DATA

problemtype:CWE-260

Trust: 1.8

problemtype:CWE-522

Trust: 1.1

problemtype:CWE-264

Trust: 0.9

sources: VULHUB: VHN-116128 // JVNDB: JVNDB-2017-003971 // NVD: CVE-2017-7925

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201704-1045

TYPE

permissions and access control issues

Trust: 0.6

sources: CNNVD: CNNVD-201704-1045

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-003971

PATCH

title:Cybersecurity Vulnerability Update - March 8 2017url:http://www.dahuasecurity.com/en/us/single.php?nid=364

Trust: 0.8

title:Security Notification DHCC-201703-01url:http://www1.dahuasecurity.com/annoucementsingle/security-notification-dhcc-201703-01-112.html

Trust: 0.8

title:Cyber Vulnerability Affecting Certain Dahua IP Cameras and Recorders (030617)url:http://us.dahuasecurity.com/en/us/Security-Bulletin_030617.php

Trust: 0.8

title:Cyber Vulnerability Affecting Certain Dahua IP Cameras and Recorders (04032017)url:http://us.dahuasecurity.com/en/us/Security-Bulletin_04032017.php

Trust: 0.8

title:Cybersecurity Statement - March 6th 2017url:http://www.dahuasecurity.com/en/us/single.php?nid=354

Trust: 0.8

title:Patches for Dahua's multiple digital video recorders and IP camera profile password vulnerabilitiesurl:https://www.cnvd.org.cn/patchInfo/show/94425

Trust: 0.6

title:Repair measures for various UOB product security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=99754

Trust: 0.6

sources: CNVD: CNVD-2017-08192 // JVNDB: JVNDB-2017-003971 // CNNVD: CNNVD-201704-1045

EXTERNAL IDS

db:NVDid:CVE-2017-7925

Trust: 3.6

db:ICS CERTid:ICSA-17-124-02

Trust: 2.8

db:BIDid:98312

Trust: 2.6

db:CNNVDid:CNNVD-201704-1045

Trust: 0.9

db:CNVDid:CNVD-2017-08192

Trust: 0.8

db:JVNid:JVNVU98841854

Trust: 0.8

db:JVNDBid:JVNDB-2017-003971

Trust: 0.8

db:IVDid:B9A8CA3D-8AC9-429C-880C-4CC25C09C01B

Trust: 0.2

db:VULHUBid:VHN-116128

Trust: 0.1

sources: IVD: b9a8ca3d-8ac9-429c-880c-4cc25c09c01b // CNVD: CNVD-2017-08192 // VULHUB: VHN-116128 // BID: 98312 // JVNDB: JVNDB-2017-003971 // CNNVD: CNNVD-201704-1045 // NVD: CVE-2017-7925

REFERENCES

url:https://ics-cert.us-cert.gov/advisories/icsa-17-124-02

Trust: 2.8

url:http://us.dahuasecurity.com/en/us/security-bulletin_030617.php

Trust: 2.3

url:http://www.securityfocus.com/bid/98312

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2017-7925

Trust: 1.4

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-7925

Trust: 0.8

url:http://jvn.jp/vu/jvnvu98841854/index.html

Trust: 0.8

url:https://github.com/mcw0/poc/blob/master/dahua-backdoor-poc.py

Trust: 0.8

url:https://github.com/mcw0/poc/blob/master/dahua-backdoor.txt

Trust: 0.8

url:www.dahuasecurity.com

Trust: 0.3

sources: CNVD: CNVD-2017-08192 // VULHUB: VHN-116128 // BID: 98312 // JVNDB: JVNDB-2017-003971 // CNNVD: CNNVD-201704-1045 // NVD: CVE-2017-7925

CREDITS

Bashis

Trust: 0.3

sources: BID: 98312

SOURCES

db:IVDid:b9a8ca3d-8ac9-429c-880c-4cc25c09c01b
db:CNVDid:CNVD-2017-08192
db:VULHUBid:VHN-116128
db:BIDid:98312
db:JVNDBid:JVNDB-2017-003971
db:CNNVDid:CNNVD-201704-1045
db:NVDid:CVE-2017-7925

LAST UPDATE DATE

2024-11-23T22:56:13.229000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2017-08192date:2017-06-05T00:00:00
db:VULHUBid:VHN-116128date:2019-10-09T00:00:00
db:BIDid:98312date:2017-05-23T16:23:00
db:JVNDBid:JVNDB-2017-003971date:2017-07-13T00:00:00
db:CNNVDid:CNNVD-201704-1045date:2019-10-17T00:00:00
db:NVDid:CVE-2017-7925date:2024-11-21T03:32:58.700

SOURCES RELEASE DATE

db:IVDid:b9a8ca3d-8ac9-429c-880c-4cc25c09c01bdate:2017-06-05T00:00:00
db:CNVDid:CNVD-2017-08192date:2017-06-05T00:00:00
db:VULHUBid:VHN-116128date:2017-05-06T00:00:00
db:BIDid:98312date:2017-05-04T00:00:00
db:JVNDBid:JVNDB-2017-003971date:2017-06-13T00:00:00
db:CNNVDid:CNNVD-201704-1045date:2017-04-21T00:00:00
db:NVDid:CVE-2017-7925date:2017-05-06T00:29:00.427