PT-2017-18842 · Dahua · Dahua Ip Ptz+1
Published
2017-11-28
·
Updated
2019-10-03
·
CVE-2017-9315
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Dahua IP camera (affected versions not specified)
Dahua IP PTZ (affected versions not specified)
Description
The issue concerns a potentially compromised algorithm used in a password reset mechanism for Dahua IP cameras and IP PTZ devices. This could allow an attacker to utilize the compromised algorithm.
Recommendations
For Dahua IP camera, consider restricting access to the password reset mechanism until a secure alternative is provided.
For Dahua IP PTZ, avoid using the temporary password feature from Dahua authorized dealers until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dahua Ip Ptz
Dahua Ip Camera