PT-2017-18842 · Dahua · Dahua Ip Ptz+1

Published

2017-11-28

·

Updated

2019-10-03

·

CVE-2017-9315

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Dahua IP camera (affected versions not specified) Dahua IP PTZ (affected versions not specified)
Description The issue concerns a potentially compromised algorithm used in a password reset mechanism for Dahua IP cameras and IP PTZ devices. This could allow an attacker to utilize the compromised algorithm.
Recommendations For Dahua IP camera, consider restricting access to the password reset mechanism until a secure alternative is provided. For Dahua IP PTZ, avoid using the temporary password feature from Dahua authorized dealers until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2017-9315
ZDI-18-130

Affected Products

Dahua Ip Ptz
Dahua Ip Camera