Vulnerabilities > CVE-2013-3612 - Credentials Management vulnerability in Dahuasecurity products

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
dahuasecurity
CWE-255
critical
exploit available

Summary

Dahua DVR appliances have a hardcoded password for (1) the root account and (2) an unspecified "backdoor" account, which makes it easier for remote attackers to obtain administrative access via authorization requests involving (a) ActiveX, (b) a standalone client, or (c) unknown other vectors.

Vulnerable Configurations

Part Description Count
Hardware
Dahuasecurity
65

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionDahua DVR 2.608.0000.0 and 2.608.GV00.0 - Authentication Bypass. CVE-2013-3612,CVE-2013-3613,CVE-2013-3614,CVE-2013-3615,CVE-2013-6117. Webapps exploit for h...
fileexploits/hardware/webapps/29673.txt
idEDB-ID:29673
last seen2016-02-03
modified2013-11-18
platformhardware
port37777
published2013-11-18
reporterJake Reynolds
sourcehttps://www.exploit-db.com/download/29673/
titleDahua DVR 2.608.0000.0 and 2.608.GV00.0 - Authentication Bypass
typewebapps

Seebug

bulletinFamilyexploit
descriptionNo description provided by source.
idSSV:83161
last seen2017-11-19
modified2014-07-01
published2014-07-01
reporterRoot
sourcehttps://www.seebug.org/vuldb/ssvid-83161
titleDahua DVR 2.608.0000.0 and 2.608.GV00.0 - Authentication Bypass