CVE-2017-7925
Dahua Security - Configuration File Disclosure
Record summary
CVE-2017-7925 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
A Password in Configuration File issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX, DH-IPC-HFW1XXX, DH-IPC-HFW2XXX, DH-IPC-HFW4XXX, DH-SD6CXX, DH-NVR1XXX, DH-HCVR4XXX, DH-HCVR5XXX, DHI-HCVR51A04HE-S3, DHI-HCVR51A08HE-S3, and DHI-HCVR58A32S-S2 devices. The password in configuration file vulnerability was identified, which could lead to a malicious user assuming the identity of a privileged user and gaining access to sensitive information.
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Dahua Technology Co., Ltd Digital Video Recorders and IP Cameras | CVE List | Dahua Technology Co., Ltd Digital Video Recorders and IP Cameras | affected |
Nuclei templates
1ProjectDiscoveryCRITICALDahua Security - Configuration File DisclosureCVSS 9.8
A Password in Configuration File issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX, DH-IPC-HFW1XXX, DH-IPC-HFW2XXX, DH-IPC-HFW4XXX, DH-SD6CXX, DH-NVR1XXX, DH-HCVR4XXX, DH-HCVR5XXX, DHI-HCVR51A04HE-S3, DHI-HCVR51A08HE-S3, and DHI-HCVR58A32S-S2 devices. The password in configuration file vulnerability was identified, which could lead to a malicious user assuming the identity of a privileged user and gaining access to sensitive information.
Impact
This vulnerability can lead to unauthorized access to sensitive information, potentially compromising the security of the system.
Remediation
To remediate this vulnerability, ensure that the configuration file is properly secured and access to it is restricted to authorized personnel only.
Source: ProjectDiscovery