CVE-2017-9317

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
23/05/2018
Last modified:
03/10/2019

Description

Privilege escalation vulnerability found in some Dahua IP devices. Attacker in possession of low privilege account can gain access to credential information of high privilege account and further obtain device information or attack the device.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:dahuasecurity:xvr5x16_firmware:*:*:*:*:*:*:*:* 3.218.0000002.1.r.171229 (excluding)
cpe:2.3:h:dahuasecurity:xvr5x16:-:*:*:*:*:*:*:*
cpe:2.3:o:dahuasecurity:xvr5x08_firmware:*:*:*:*:*:*:*:* 3.218.0000002.1.r.171229 (excluding)
cpe:2.3:h:dahuasecurity:xvr5x08:-:*:*:*:*:*:*:*
cpe:2.3:o:dahuasecurity:xvr5x04_firmware:*:*:*:*:*:*:*:* 3.218.0000002.1.r.171229 (excluding)
cpe:2.3:h:dahuasecurity:xvr5x04:-:*:*:*:*:*:*:*
cpe:2.3:o:dahuasecurity:xvr7x16_firmware:*:*:*:*:*:*:*:* 3.218.0000002.1.r.171229 (excluding)
cpe:2.3:h:dahuasecurity:xvr7x16:-:*:*:*:*:*:*:*
cpe:2.3:o:dahuasecurity:ipc-hdbw4xxx_firmware:*:*:*:*:*:*:*:* 2.622.0000000.18.r.20171110 (excluding)
cpe:2.3:h:dahuasecurity:ipc-hdbw4xxx:-:*:*:*:*:*:*:*
cpe:2.3:o:dahuasecurity:ipc-hdbw4xxx_firmware:*:*:*:*:*:*:*:* 2.621.0000.28.r.20170912 (excluding)
cpe:2.3:h:dahuasecurity:ipc-hdbw4xxx:-:*:*:*:*:*:*:*
cpe:2.3:o:dahuasecurity:ipc-hdbw5xxx_firmware:*:*:*:*:*:*:*:* 2.622.0000000.18.r.20171110 (excluding)
cpe:2.3:h:dahuasecurity:ipc-hdbw5xxx:-:*:*:*:*:*:*:*
cpe:2.3:o:dahuasecurity:ipc-hdbw5xxx_firmware:*:*:*:*:*:*:*:* 2.621.0000.28.r.20170912 (excluding)