CVE-2017-6343
8.1
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 5.9
Source: NVD
Description
The web interface on Dahua DHI-HCVR7216A-S3 devices with NVR Firmware 3.210.0001.10 2016-06-06, Camera Firmware 2.400.0000.28.R 2016-03-29, and SmartPSS Software 1.16.1 2017-01-19 allows remote attackers to obtain login access by leveraging knowledge of the MD5 Admin Hash without knowledge of the corresponding password, a different vulnerability than CVE-2013-6117.
Affected (3)
Products: Dahuasecurity: Camera Firmware, Nvr Firmware, Smartpss Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.400.0000.28.r | |
| Version 3.210.0001.10 | |
| Version 1.16.1 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Dhi Hcvr7216a S3 | All versions |
References (4)
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.