CVE-2017-6432
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered on Dahua DHI-HCVR7216A-S3 3.210.0001.10 build 2016-06-06 devices. The Dahua DVR Protocol, which operates on TCP Port 37777, is an unencrypted, binary protocol. Performing a Man-in-the-Middle attack allows both sniffing and injections of packets, which allows creation of fully privileged new users, in addition to capture of sensitive information.
Se ha descubierto un problema en dispositivos Dahua DHI-HCVR7216A-S3 3.210.0001.10 build 2016-06-06. El Dahua DVR Protocol, que opera en el puerto TCP 37777, es un protocolo binario sin cifrar. La realización de un ataque Man-in-the-Middle permite tanto la escucha como la inyección de paquetes, lo que permite la creación de nuevos usuarios con privilegios completos, además de capturar la información sensible.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-03-02 CVE Reserved
- 2017-03-09 CVE Published
- 2024-08-05 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-319: Cleartext Transmission of Sensitive Information
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://nullku7.github.io/stuff/exploit/dahua/2017/03/09/dahua-nvr-authbypass.html | Third Party Advisory | |
https://twitter.com/null_ku7/status/839814344351240193 | Media Coverage |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Dahuasecurity Search vendor "Dahuasecurity" | Nvr Firmware Search vendor "Dahuasecurity" for product "Nvr Firmware" | 3.210.0001.10 Search vendor "Dahuasecurity" for product "Nvr Firmware" and version "3.210.0001.10" | - |
Affected
| in | Dahuasecurity Search vendor "Dahuasecurity" | Dhi-hcvr7216a-s3 Search vendor "Dahuasecurity" for product "Dhi-hcvr7216a-s3" | - | - |
Safe
|