Vulnerabilities > CVE-2013-3612 - Credentials Management vulnerability in Dahuasecurity products

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
dahuasecurity
CWE-255
exploit available

Summary

Dahua DVR appliances have a hardcoded password for (1) the root account and (2) an unspecified "backdoor" account, which makes it easier for remote attackers to obtain administrative access via authorization requests involving (a) ActiveX, (b) a standalone client, or (c) unknown other vectors.

Vulnerable Configurations

Part Description Count
Hardware
Dahuasecurity
65

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionDahua DVR 2.608.0000.0 and 2.608.GV00.0 - Authentication Bypass. CVE-2013-3612,CVE-2013-3613,CVE-2013-3614,CVE-2013-3615,CVE-2013-6117. Webapps exploit for h...
fileexploits/hardware/webapps/29673.txt
idEDB-ID:29673
last seen2016-02-03
modified2013-11-18
platformhardware
port37777
published2013-11-18
reporterJake Reynolds
sourcehttps://www.exploit-db.com/download/29673/
titleDahua DVR 2.608.0000.0 and 2.608.GV00.0 - Authentication Bypass
typewebapps

Seebug

bulletinFamilyexploit
descriptionNo description provided by source.
idSSV:83161
last seen2017-11-19
modified2014-07-01
published2014-07-01
reporterRoot
sourcehttps://www.seebug.org/vuldb/ssvid-83161
titleDahua DVR 2.608.0000.0 and 2.608.GV00.0 - Authentication Bypass