CVE-2017-9317
EUVD-2017-1825223.05.2018, 15:29
Privilege escalation vulnerability found in some Dahua IP devices. Attacker in possession of low privilege account can gain access to credential information of high privilege account and further obtain device information or attack the device.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| dahuasecurity | xvr5x16_firmware | 𝑥 < 3.218.0000002.1.r.171229 |
| dahuasecurity | xvr5x08_firmware | 𝑥 < 3.218.0000002.1.r.171229 |
| dahuasecurity | xvr5x04_firmware | 𝑥 < 3.218.0000002.1.r.171229 |
| dahuasecurity | xvr7x16_firmware | 𝑥 < 3.218.0000002.1.r.171229 |
| dahuasecurity | ipc-hdbw4xxx_firmware | 𝑥 < 2.622.0000000.18.r.20171110 |
| dahuasecurity | ipc-hdbw4xxx_firmware | 𝑥 < 2.621.0000.28.r.20170912 |
| dahuasecurity | ipc-hdbw5xxx_firmware | 𝑥 < 2.622.0000000.18.r.20171110 |
| dahuasecurity | ipc-hdbw5xxx_firmware | 𝑥 < 2.621.0000.28.r.20170912 |
𝑥
= Vulnerable software versions