CVE-2017-9314
 
Severity Score
8.8
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Authentication vulnerability found in Dahua NVR models NVR50XX, NVR52XX, NVR54XX, NVR58XX with software before DH_NVR5xxx_Eng_P_V2.616.0000.0.R.20171102. Attacker could exploit this vulnerability to gain access to additional operations by means of forging json message.
Se ha encontrado una vulnerabilidad de autenticación en Dahua NVR, modelos NVR50XX, NVR52XX, NVR54XX y NVR58XX con software anterior a DH_NVR5xxx_Eng_P_V2.616.0000.0.R.20171102. Un atacante podría explotar esta vulnerabilidad para obtener acceso a operaciones adicionales por medio de la falsificación de un mensaje json.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2017-05-30 CVE Reserved
- 2017-11-13 CVE Published
- 2023-03-08 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-287: Improper Authentication
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Dahuasecurity Search vendor "Dahuasecurity" | Nvr5464-16p-4ks2 Firmware Search vendor "Dahuasecurity" for product "Nvr5464-16p-4ks2 Firmware" | < dh_nvr5464_eng_p_v2.616.0000.0.r.20171102 Search vendor "Dahuasecurity" for product "Nvr5464-16p-4ks2 Firmware" and version " < dh_nvr5464_eng_p_v2.616.0000.0.r.20171102" | - |
Affected
| in | Dahuasecurity Search vendor "Dahuasecurity" | Nvr5464-16p-4ks2 Search vendor "Dahuasecurity" for product "Nvr5464-16p-4ks2" | - | - |
Safe
|
Dahuasecurity Search vendor "Dahuasecurity" | Nvr5208-8p-4ks2 Firmware Search vendor "Dahuasecurity" for product "Nvr5208-8p-4ks2 Firmware" | < dh_nvr5208_eng_p_v2.616.0000.0.r.20171102 Search vendor "Dahuasecurity" for product "Nvr5208-8p-4ks2 Firmware" and version " < dh_nvr5208_eng_p_v2.616.0000.0.r.20171102" | - |
Affected
| in | Dahuasecurity Search vendor "Dahuasecurity" | Nvr5208-8p-4ks2 Search vendor "Dahuasecurity" for product "Nvr5208-8p-4ks2" | - | - |
Safe
|
Dahuasecurity Search vendor "Dahuasecurity" | Nvr5432-16p-4ks2 Firmware Search vendor "Dahuasecurity" for product "Nvr5432-16p-4ks2 Firmware" | < dh_nvr5432_eng_p_v2.616.0000.0.r.20171102 Search vendor "Dahuasecurity" for product "Nvr5432-16p-4ks2 Firmware" and version " < dh_nvr5432_eng_p_v2.616.0000.0.r.20171102" | - |
Affected
| in | Dahuasecurity Search vendor "Dahuasecurity" | Nvr5432-16p-4ks2 Search vendor "Dahuasecurity" for product "Nvr5432-16p-4ks2" | - | - |
Safe
|
Dahuasecurity Search vendor "Dahuasecurity" | Nvr5416-16p-4ks2 Firmware Search vendor "Dahuasecurity" for product "Nvr5416-16p-4ks2 Firmware" | < dh_nvr5416_eng_p_v2.616.0000.0.r.20171102 Search vendor "Dahuasecurity" for product "Nvr5416-16p-4ks2 Firmware" and version " < dh_nvr5416_eng_p_v2.616.0000.0.r.20171102" | - |
Affected
| in | Dahuasecurity Search vendor "Dahuasecurity" | Nvr5416-16p-4ks2 Search vendor "Dahuasecurity" for product "Nvr5416-16p-4ks2" | - | - |
Safe
|
Dahuasecurity Search vendor "Dahuasecurity" | Nvr5464-4ks2 Firmware Search vendor "Dahuasecurity" for product "Nvr5464-4ks2 Firmware" | < dh_nvr5464_eng_p_v2.616.0000.0.r.20171102 Search vendor "Dahuasecurity" for product "Nvr5464-4ks2 Firmware" and version " < dh_nvr5464_eng_p_v2.616.0000.0.r.20171102" | - |
Affected
| in | Dahuasecurity Search vendor "Dahuasecurity" | Nvr5464-4ks2 Search vendor "Dahuasecurity" for product "Nvr5464-4ks2" | - | - |
Safe
|
Dahuasecurity Search vendor "Dahuasecurity" | Nvr5432-4ks2 Firmware Search vendor "Dahuasecurity" for product "Nvr5432-4ks2 Firmware" | < dh_nvr5432_eng_p_v2.616.0000.0.r.20171102 Search vendor "Dahuasecurity" for product "Nvr5432-4ks2 Firmware" and version " < dh_nvr5432_eng_p_v2.616.0000.0.r.20171102" | - |
Affected
| in | Dahuasecurity Search vendor "Dahuasecurity" | Nvr5432-4ks2 Search vendor "Dahuasecurity" for product "Nvr5432-4ks2" | - | - |
Safe
|
Dahuasecurity Search vendor "Dahuasecurity" | Nvr5416-4ks2 Firmware Search vendor "Dahuasecurity" for product "Nvr5416-4ks2 Firmware" | < dh_nvr5416_eng_p_v2.616.0000.0.r.20171102 Search vendor "Dahuasecurity" for product "Nvr5416-4ks2 Firmware" and version " < dh_nvr5416_eng_p_v2.616.0000.0.r.20171102" | - |
Affected
| in | Dahuasecurity Search vendor "Dahuasecurity" | Nvr5416-4ks2 Search vendor "Dahuasecurity" for product "Nvr5416-4ks2" | - | - |
Safe
|
Dahuasecurity Search vendor "Dahuasecurity" | Nvr5232-16p-4ks2 Firmware Search vendor "Dahuasecurity" for product "Nvr5232-16p-4ks2 Firmware" | < dh_nvr5232_eng_p_v2.616.0000.0.r.20171102 Search vendor "Dahuasecurity" for product "Nvr5232-16p-4ks2 Firmware" and version " < dh_nvr5232_eng_p_v2.616.0000.0.r.20171102" | - |
Affected
| in | Dahuasecurity Search vendor "Dahuasecurity" | Nvr5232-16p-4ks2 Search vendor "Dahuasecurity" for product "Nvr5232-16p-4ks2" | - | - |
Safe
|
Dahuasecurity Search vendor "Dahuasecurity" | Nvr5216-16p-4ks2 Firmware Search vendor "Dahuasecurity" for product "Nvr5216-16p-4ks2 Firmware" | < dh_nvr5216_eng_p_v2.616.0000.0.r.20171102 Search vendor "Dahuasecurity" for product "Nvr5216-16p-4ks2 Firmware" and version " < dh_nvr5216_eng_p_v2.616.0000.0.r.20171102" | - |
Affected
| in | Dahuasecurity Search vendor "Dahuasecurity" | Nvr5216-16p-4ks2 Search vendor "Dahuasecurity" for product "Nvr5216-16p-4ks2" | - | - |
Safe
|
Dahuasecurity Search vendor "Dahuasecurity" | Nvr5232-8p-4ks2 Firmware Search vendor "Dahuasecurity" for product "Nvr5232-8p-4ks2 Firmware" | < dh_nvr5232_eng_p_v2.616.0000.0.r.20171102 Search vendor "Dahuasecurity" for product "Nvr5232-8p-4ks2 Firmware" and version " < dh_nvr5232_eng_p_v2.616.0000.0.r.20171102" | - |
Affected
| in | Dahuasecurity Search vendor "Dahuasecurity" | Nvr5232-8p-4ks2 Search vendor "Dahuasecurity" for product "Nvr5232-8p-4ks2" | - | - |
Safe
|
Dahuasecurity Search vendor "Dahuasecurity" | Nvr5216-8p-4ks2 Firmware Search vendor "Dahuasecurity" for product "Nvr5216-8p-4ks2 Firmware" | < dh_nvr5216_eng_p_v2.616.0000.0.r.20171102 Search vendor "Dahuasecurity" for product "Nvr5216-8p-4ks2 Firmware" and version " < dh_nvr5216_eng_p_v2.616.0000.0.r.20171102" | - |
Affected
| in | Dahuasecurity Search vendor "Dahuasecurity" | Nvr5216-8p-4ks2 Search vendor "Dahuasecurity" for product "Nvr5216-8p-4ks2" | - | - |
Safe
|
Dahuasecurity Search vendor "Dahuasecurity" | Nvr5232-4ks2 Firmware Search vendor "Dahuasecurity" for product "Nvr5232-4ks2 Firmware" | < dh_nvr5232_eng_p_v2.616.0000.0.r.20171102 Search vendor "Dahuasecurity" for product "Nvr5232-4ks2 Firmware" and version " < dh_nvr5232_eng_p_v2.616.0000.0.r.20171102" | - |
Affected
| in | Dahuasecurity Search vendor "Dahuasecurity" | Nvr5232-4ks2 Search vendor "Dahuasecurity" for product "Nvr5232-4ks2" | - | - |
Safe
|
Dahuasecurity Search vendor "Dahuasecurity" | Nvr5216-4ks2 Firmware Search vendor "Dahuasecurity" for product "Nvr5216-4ks2 Firmware" | < dh_nvr5216_eng_p_v2.616.0000.0.r.20171102 Search vendor "Dahuasecurity" for product "Nvr5216-4ks2 Firmware" and version " < dh_nvr5216_eng_p_v2.616.0000.0.r.20171102" | - |
Affected
| in | Dahuasecurity Search vendor "Dahuasecurity" | Nvr5216-4ks2 Search vendor "Dahuasecurity" for product "Nvr5216-4ks2" | - | - |
Safe
|
Dahuasecurity Search vendor "Dahuasecurity" | Nvr5208-4ks2 Firmware Search vendor "Dahuasecurity" for product "Nvr5208-4ks2 Firmware" | < dh_nvr5208_eng_p_v2.616.0000.0.r.20171102 Search vendor "Dahuasecurity" for product "Nvr5208-4ks2 Firmware" and version " < dh_nvr5208_eng_p_v2.616.0000.0.r.20171102" | - |
Affected
| in | Dahuasecurity Search vendor "Dahuasecurity" | Nvr5208-4ks2 Search vendor "Dahuasecurity" for product "Nvr5208-4ks2" | - | - |
Safe
|
Dahuasecurity Search vendor "Dahuasecurity" | Nvr5816-4ks2 Firmware Search vendor "Dahuasecurity" for product "Nvr5816-4ks2 Firmware" | < dh_nvr5816_eng_p_v2.616.0000.0.r.20171102 Search vendor "Dahuasecurity" for product "Nvr5816-4ks2 Firmware" and version " < dh_nvr5816_eng_p_v2.616.0000.0.r.20171102" | - |
Affected
| in | Dahuasecurity Search vendor "Dahuasecurity" | Nvr5816-4ks2 Search vendor "Dahuasecurity" for product "Nvr5816-4ks2" | - | - |
Safe
|
Dahuasecurity Search vendor "Dahuasecurity" | Nvr5832-4ks2 Firmware Search vendor "Dahuasecurity" for product "Nvr5832-4ks2 Firmware" | < dh_nvr5832_eng_p_v2.616.0000.0.r.20171102 Search vendor "Dahuasecurity" for product "Nvr5832-4ks2 Firmware" and version " < dh_nvr5832_eng_p_v2.616.0000.0.r.20171102" | - |
Affected
| in | Dahuasecurity Search vendor "Dahuasecurity" | Nvr5832-4ks2 Search vendor "Dahuasecurity" for product "Nvr5832-4ks2" | - | - |
Safe
|
Dahuasecurity Search vendor "Dahuasecurity" | Nvr5864-4ks2 Firmware Search vendor "Dahuasecurity" for product "Nvr5864-4ks2 Firmware" | < dh_nvr5864_eng_p_v2.616.0000.0.r.20171102 Search vendor "Dahuasecurity" for product "Nvr5864-4ks2 Firmware" and version " < dh_nvr5864_eng_p_v2.616.0000.0.r.20171102" | - |
Affected
| in | Dahuasecurity Search vendor "Dahuasecurity" | Nvr5864-4ks2 Search vendor "Dahuasecurity" for product "Nvr5864-4ks2" | - | - |
Safe
|
Dahuasecurity Search vendor "Dahuasecurity" | Nvr5864-16p-4ks2 Firmware Search vendor "Dahuasecurity" for product "Nvr5864-16p-4ks2 Firmware" | < dh_nvr5864_eng_p_v2.616.0000.0.r.20171102 Search vendor "Dahuasecurity" for product "Nvr5864-16p-4ks2 Firmware" and version " < dh_nvr5864_eng_p_v2.616.0000.0.r.20171102" | - |
Affected
| in | Dahuasecurity Search vendor "Dahuasecurity" | Nvr5864-16p-4ks2 Search vendor "Dahuasecurity" for product "Nvr5864-16p-4ks2" | - | - |
Safe
|
Dahuasecurity Search vendor "Dahuasecurity" | Nvr5832-16p-4ks2 Firmware Search vendor "Dahuasecurity" for product "Nvr5832-16p-4ks2 Firmware" | < dh_nvr5832_eng_p_v2.616.0000.0.r.20171102 Search vendor "Dahuasecurity" for product "Nvr5832-16p-4ks2 Firmware" and version " < dh_nvr5832_eng_p_v2.616.0000.0.r.20171102" | - |
Affected
| in | Dahuasecurity Search vendor "Dahuasecurity" | Nvr5832-16p-4ks2 Search vendor "Dahuasecurity" for product "Nvr5832-16p-4ks2" | - | - |
Safe
|
Dahuasecurity Search vendor "Dahuasecurity" | Nvr5816-16p-4ks2 Firmware Search vendor "Dahuasecurity" for product "Nvr5816-16p-4ks2 Firmware" | < dh_nvr5816_eng_p_v2.616.0000.0.r.20171102 Search vendor "Dahuasecurity" for product "Nvr5816-16p-4ks2 Firmware" and version " < dh_nvr5816_eng_p_v2.616.0000.0.r.20171102" | - |
Affected
| in | Dahuasecurity Search vendor "Dahuasecurity" | Nvr5816-16p-4ks2 Search vendor "Dahuasecurity" for product "Nvr5816-16p-4ks2" | - | - |
Safe
|
Dahuasecurity Search vendor "Dahuasecurity" | Nvr5424-24p-4ks2 Firmware Search vendor "Dahuasecurity" for product "Nvr5424-24p-4ks2 Firmware" | < dh_nvr5424_eng_p_v2.616.0000.0.r.20171102 Search vendor "Dahuasecurity" for product "Nvr5424-24p-4ks2 Firmware" and version " < dh_nvr5424_eng_p_v2.616.0000.0.r.20171102" | - |
Affected
| in | Dahuasecurity Search vendor "Dahuasecurity" | Nvr5424-24p-4ks2 Search vendor "Dahuasecurity" for product "Nvr5424-24p-4ks2" | - | - |
Safe
|
Dahuasecurity Search vendor "Dahuasecurity" | Nvr5224-24p-4ks2 Firmware Search vendor "Dahuasecurity" for product "Nvr5224-24p-4ks2 Firmware" | < dh_nvr5224_eng_p_v2.616.0000.0.r.20171102 Search vendor "Dahuasecurity" for product "Nvr5224-24p-4ks2 Firmware" and version " < dh_nvr5224_eng_p_v2.616.0000.0.r.20171102" | - |
Affected
| in | Dahuasecurity Search vendor "Dahuasecurity" | Nvr5224-24p-4ks2 Search vendor "Dahuasecurity" for product "Nvr5224-24p-4ks2" | - | - |
Safe
|