PT-2017-17613 · Dahua · Dahua Ip Camera
Published
2017-03-30
·
Updated
2019-10-03
·
CVE-2017-7253
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Dahua IP Camera devices version 3.200.0001.6
Description
The issue allows exploitation of Dahua IP Camera devices by using default low-privilege credentials to list all users via a request to a certain URI, and then logging in with admin credentials to obtain full control of the target IP camera. During exploitation, JSON objects are encountered, including a "Component error: login challenge!" message and a result indicating a successful admin login.
Recommendations
For Dahua IP Camera devices version 3.200.0001.6, update the device to a version that is not affected by this issue, or change the default low-privilege credentials and admin credentials to prevent unauthorized access. As a temporary workaround, consider restricting access to the URI used in the exploitation steps to minimize the risk of exploitation.
Exploit
Fix
Insecure Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dahua Ip Camera