// For flags

CVE-2017-7925

 

Severity Score

9.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A Password in Configuration File issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX, DH-IPC-HFW1XXX, DH-IPC-HFW2XXX, DH-IPC-HFW4XXX, DH-SD6CXX, DH-NVR1XXX, DH-HCVR4XXX, DH-HCVR5XXX, DHI-HCVR51A04HE-S3, DHI-HCVR51A08HE-S3, and DHI-HCVR58A32S-S2 devices. The password in configuration file vulnerability was identified, which could lead to a malicious user assuming the identity of a privileged user and gaining access to sensitive information.

Se detectó un problema de Contraseña en el Archivo de Configuración en cámaras DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX, DH-IPC-HFW1XXX, DH-IPC-HFW2XXX, DH-IPC-HFW4XXX, DH-SD6CXX, DH-NVR1XXX, DH-HCVR4XXX, DH-HCVR5XXX, DHI-HCVR51A04HE-S3, DHI-HCVR51A08HE-S3 y DHI-HCVR58A32S-S2, de Dahua . Se identificó una vulnerabilidad de contraseña en el archivo de configuración, lo que podría conllevar a un usuario malicioso a asumir la identidad de un usuario con privilegios y conseguir acceso a información confidencial.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2017-04-18 CVE Reserved
  • 2017-05-06 CVE Published
  • 2024-08-05 CVE Updated
  • 2024-09-12 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-260: Password in Configuration File
  • CWE-522: Insufficiently Protected Credentials
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Dahuasecurity
Search vendor "Dahuasecurity"
Dh-ipc-hdbw23a0rn-zs Firmware
Search vendor "Dahuasecurity" for product "Dh-ipc-hdbw23a0rn-zs Firmware"
--
Affected
in Dahuasecurity
Search vendor "Dahuasecurity"
Dh-ipc-hdbw23a0rn-zs
Search vendor "Dahuasecurity" for product "Dh-ipc-hdbw23a0rn-zs"
--
Safe
Dahuasecurity
Search vendor "Dahuasecurity"
Dh-ipc-hdbw13a0sn Firmware
Search vendor "Dahuasecurity" for product "Dh-ipc-hdbw13a0sn Firmware"
--
Affected
in Dahuasecurity
Search vendor "Dahuasecurity"
Dh-ipc-hdbw13a0sn
Search vendor "Dahuasecurity" for product "Dh-ipc-hdbw13a0sn"
--
Safe
Dahuasecurity
Search vendor "Dahuasecurity"
Dh-ipc-hdw1xxx Firmware
Search vendor "Dahuasecurity" for product "Dh-ipc-hdw1xxx Firmware"
--
Affected
in Dahuasecurity
Search vendor "Dahuasecurity"
Dh-ipc-hdw1xxx
Search vendor "Dahuasecurity" for product "Dh-ipc-hdw1xxx"
--
Safe
Dahuasecurity
Search vendor "Dahuasecurity"
Dh-ipc-hdw2xxx Firmware
Search vendor "Dahuasecurity" for product "Dh-ipc-hdw2xxx Firmware"
--
Affected
in Dahuasecurity
Search vendor "Dahuasecurity"
Dh-ipc-hdw2xxx
Search vendor "Dahuasecurity" for product "Dh-ipc-hdw2xxx"
--
Safe
Dahuasecurity
Search vendor "Dahuasecurity"
Dh-ipc-hdw4xxx Firmware
Search vendor "Dahuasecurity" for product "Dh-ipc-hdw4xxx Firmware"
--
Affected
in Dahuasecurity
Search vendor "Dahuasecurity"
Dh-ipc-hdw4xxx
Search vendor "Dahuasecurity" for product "Dh-ipc-hdw4xxx"
--
Safe
Dahuasecurity
Search vendor "Dahuasecurity"
Dh-ipc-hfw1xxx Firmware
Search vendor "Dahuasecurity" for product "Dh-ipc-hfw1xxx Firmware"
--
Affected
in Dahuasecurity
Search vendor "Dahuasecurity"
Dh-ipc-hfw1xxx
Search vendor "Dahuasecurity" for product "Dh-ipc-hfw1xxx"
--
Safe
Dahuasecurity
Search vendor "Dahuasecurity"
Dh-ipc-hfw2xxx Firmware
Search vendor "Dahuasecurity" for product "Dh-ipc-hfw2xxx Firmware"
--
Affected
in Dahuasecurity
Search vendor "Dahuasecurity"
Dh-ipc-hfw2xxx
Search vendor "Dahuasecurity" for product "Dh-ipc-hfw2xxx"
--
Safe
Dahuasecurity
Search vendor "Dahuasecurity"
Dh-ipc-hfw4xxx Firmware
Search vendor "Dahuasecurity" for product "Dh-ipc-hfw4xxx Firmware"
--
Affected
in Dahuasecurity
Search vendor "Dahuasecurity"
Dh-ipc-hfw4xxx
Search vendor "Dahuasecurity" for product "Dh-ipc-hfw4xxx"
--
Safe
Dahuasecurity
Search vendor "Dahuasecurity"
Dh-sd6cxx Firmware
Search vendor "Dahuasecurity" for product "Dh-sd6cxx Firmware"
--
Affected
in Dahuasecurity
Search vendor "Dahuasecurity"
Dh-sd6cxx
Search vendor "Dahuasecurity" for product "Dh-sd6cxx"
--
Safe
Dahuasecurity
Search vendor "Dahuasecurity"
Dh-nvr1xxx Firmware
Search vendor "Dahuasecurity" for product "Dh-nvr1xxx Firmware"
--
Affected
in Dahuasecurity
Search vendor "Dahuasecurity"
Dh-nvr1xxx
Search vendor "Dahuasecurity" for product "Dh-nvr1xxx"
--
Safe
Dahuasecurity
Search vendor "Dahuasecurity"
Dh-hcvr4xxx Firmware
Search vendor "Dahuasecurity" for product "Dh-hcvr4xxx Firmware"
--
Affected
in Dahuasecurity
Search vendor "Dahuasecurity"
Ddh-hcvr4xxx
Search vendor "Dahuasecurity" for product "Ddh-hcvr4xxx"
--
Safe
Dahuasecurity
Search vendor "Dahuasecurity"
Dh-hcvr5xxx Firmware
Search vendor "Dahuasecurity" for product "Dh-hcvr5xxx Firmware"
--
Affected
in Dahuasecurity
Search vendor "Dahuasecurity"
Dh-hcvr5xxx
Search vendor "Dahuasecurity" for product "Dh-hcvr5xxx"
--
Safe
Dahuasecurity
Search vendor "Dahuasecurity"
Dhi-hcvr51a04he-s3 Firmware
Search vendor "Dahuasecurity" for product "Dhi-hcvr51a04he-s3 Firmware"
--
Affected
in Dahuasecurity
Search vendor "Dahuasecurity"
Dhi-hcvr51a04he-s3
Search vendor "Dahuasecurity" for product "Dhi-hcvr51a04he-s3"
--
Safe
Dahuasecurity
Search vendor "Dahuasecurity"
Dhi-hcvr51a08he-s3 Firmware
Search vendor "Dahuasecurity" for product "Dhi-hcvr51a08he-s3 Firmware"
--
Affected
in Dahuasecurity
Search vendor "Dahuasecurity"
Dhi-hcvr51a08he-s3
Search vendor "Dahuasecurity" for product "Dhi-hcvr51a08he-s3"
--
Safe
Dahuasecurity
Search vendor "Dahuasecurity"
Dhi-hcvr58a32s-s2 Firmware
Search vendor "Dahuasecurity" for product "Dhi-hcvr58a32s-s2 Firmware"
--
Affected
in Dahuasecurity
Search vendor "Dahuasecurity"
Dhi-hcvr58a32s-s2
Search vendor "Dahuasecurity" for product "Dhi-hcvr58a32s-s2"
--
Safe