← Back

CVE-2017-7927

nvd nist
Published: May 6, 2017Modified: May 13, 2026

JSON object

Loading...
7.3
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Exploitability: 3.9 / Impact: 3.4
Source: NVD

Description

A Use of Password Hash Instead of Password for Authentication issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX, DH-IPC-HFW1XXX, DH-IPC-HFW2XXX, DH-IPC-HFW4XXX, DH-SD6CXX, DH-NVR1XXX, DH-HCVR4XXX, DH-HCVR5XXX, DHI-HCVR51A04HE-S3, DHI-HCVR51A08HE-S3, and DHI-HCVR58A32S-S2 devices. The use of password hash instead of password for authentication vulnerability was identified, which could allow a malicious user to bypass authentication without obtaining the actual password.

Affected (15)

15 products
Dh Ipc Hdbw23a0rn Zs Firmware
Dh Ipc Hdbw13a0sn Firmware
Dh Ipc Hdw1xxx Firmware
Dh Ipc Hdw2xxx Firmware
Dh Ipc Hdw4xxx Firmware
Dh Ipc Hfw1xxx Firmware
Dh Ipc Hfw2xxx Firmware
Dh Ipc Hfw4xxx Firmware
Dh Sd6cxx Firmware
Dh Nvr1xxx Firmware
Dh Hcvr4xxx Firmware
Dh Hcvr5xxx Firmware
Dhi Hcvr51a04he S3 Firmware
Dhi Hcvr51a08he S3 Firmware
Dhi Hcvr58a32s S2 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Dahuasecurity
Dh Ipc Hdbw23a0rn Zs
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Dahuasecurity
Dh Ipc Hdbw13a0sn
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Dahuasecurity
Dh Ipc Hdw1xxx
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Dahuasecurity
Dh Ipc Hdw2xxx
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Dahuasecurity
Dh Ipc Hdw4xxx
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Dahuasecurity
Dh Ipc Hfw1xxx
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Dahuasecurity
Dh Ipc Hfw2xxx
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Dahuasecurity
Dh Ipc Hfw4xxx
All versions
Configuration I
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Dahuasecurity
Dh Sd6cxx
All versions
Configuration J
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Dahuasecurity
Dh Nvr1xxx
All versions
Configuration K
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Dahuasecurity
Ddh Hcvr4xxx
All versions
Configuration L
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Dahuasecurity
Dh Hcvr5xxx
All versions
Configuration M
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Dahuasecurity
Dhi Hcvr51a04he S3
All versions
Configuration N
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Dahuasecurity
Dhi Hcvr51a08he S3
All versions
Configuration O
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Dahuasecurity
Dhi Hcvr58a32s S2
All versions

References (6)

Source: ics-cert@hq.dhs.gov
PatchVendor Advisory
Source: ics-cert@hq.dhs.gov
Third Party AdvisoryVDB Entry
Source: ics-cert@hq.dhs.gov
MitigationThird Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationThird Party AdvisoryUS Government Resource

Timeline

No history available yet.