HIGH · 8.8

CVE-2017-9317

Privilege escalation vulnerability found in some Dahua IP devices. Attacker in possession of low privilege account can gain access to credential information of high privilege account and further obtai...

Vulnerability Description

Privilege escalation vulnerability found in some Dahua IP devices. Attacker in possession of low privilege account can gain access to credential information of high privilege account and further obtain device information or attack the device.

CVSS Score

8.8

HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
DahuasecurityXvr5X16 Firmware< 3.218.0000002.1.r.171229
DahuasecurityXvr5X16-
DahuasecurityXvr5X08 Firmware< 3.218.0000002.1.r.171229
DahuasecurityXvr5X08-
DahuasecurityXvr5X04 Firmware< 3.218.0000002.1.r.171229
DahuasecurityXvr5X04-
DahuasecurityXvr7X16 Firmware< 3.218.0000002.1.r.171229
DahuasecurityXvr7X16-
DahuasecurityIpc-Hdbw4Xxx Firmware< 2.622.0000000.18.r.20171110
DahuasecurityIpc-Hdbw4Xxx-
DahuasecurityIpc-Hdbw5Xxx Firmware< 2.622.0000000.18.r.20171110
DahuasecurityIpc-Hdbw5Xxx-

References

FAQ

What is CVE-2017-9317?

CVE-2017-9317 is a vulnerability with a CVSS score of 8.8 (HIGH). Privilege escalation vulnerability found in some Dahua IP devices. Attacker in possession of low privilege account can gain access to credential information of high privilege account and further obtai...

How severe is CVE-2017-9317?

CVE-2017-9317 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2017-9317?

Check the references section above for vendor advisories and patch information. Affected products include: Dahuasecurity Xvr5X16 Firmware, Dahuasecurity Xvr5X16, Dahuasecurity Xvr5X08 Firmware, Dahuasecurity Xvr5X08, Dahuasecurity Xvr5X04 Firmware.