PT-2017-17613 · Dahua · Dahua Ip Camera

Published

2017-03-30

·

Updated

2019-10-03

·

CVE-2017-7253

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Dahua IP Camera devices version 3.200.0001.6
Description The issue allows exploitation of Dahua IP Camera devices by using default low-privilege credentials to list all users via a request to a certain URI, and then logging in with admin credentials to obtain full control of the target IP camera. During exploitation, JSON objects are encountered, including a "Component error: login challenge!" message and a result indicating a successful admin login.
Recommendations For Dahua IP Camera devices version 3.200.0001.6, update the device to a version that is not affected by this issue, or change the default low-privilege credentials and admin credentials to prevent unauthorized access. As a temporary workaround, consider restricting access to the URI used in the exploitation steps to minimize the risk of exploitation.

Exploit

Fix

Insecure Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-7253

Affected Products

Dahua Ip Camera