Record summary

CVE-2017-7925 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

A Password in Configuration File issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX, DH-IPC-HFW1XXX, DH-IPC-HFW2XXX, DH-IPC-HFW4XXX, DH-SD6CXX, DH-NVR1XXX, DH-HCVR4XXX, DH-HCVR5XXX, DHI-HCVR51A04HE-S3, DHI-HCVR51A08HE-S3, and DHI-HCVR58A32S-S2 devices. The password in configuration file vulnerability was identified, which could lead to a malicious user assuming the identity of a privileged user and gaining access to sensitive information.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

Dahua Technology Co., Ltd Digital Video Recorders and IP Cameras

CVE ListDahua Technology Co., Ltd Digital Video Recorders and IP Camerasaffected

Nuclei templates

1
ProjectDiscoveryCRITICALDahua Security - Configuration File DisclosureCVSS 9.8

A Password in Configuration File issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX, DH-IPC-HFW1XXX, DH-IPC-HFW2XXX, DH-IPC-HFW4XXX, DH-SD6CXX, DH-NVR1XXX, DH-HCVR4XXX, DH-HCVR5XXX, DHI-HCVR51A04HE-S3, DHI-HCVR51A08HE-S3, and DHI-HCVR58A32S-S2 devices. The password in configuration file vulnerability was identified, which could lead to a malicious user assuming the identity of a privileged user and gaining access to sensitive information.

Impact

This vulnerability can lead to unauthorized access to sensitive information, potentially compromising the security of the system.

Remediation

To remediate this vulnerability, ensure that the configuration file is properly secured and access to it is restricted to authorized personnel only.

WeaknessesCWE-522CWE-260
AuthorsE1A, none
Template tagscvecve2017dahuacameradahuasecurityvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:o:dahuasecurity:dh-ipc-hdbw23a0rn-zs_firmware:-:*:*:*:*:*:*:*
Shodan: http.favicon.hash:2019488876
FOFA: icon_hash=2019488876

Source: ProjectDiscovery

References

4