CVE-2013-3612: Critical severity dahua security dvr0404hd-a vulnerability
Dahua DVR appliances have a hardcoded password for (1) the root account and (2) an unspecified "backdoor" account, which makes it easier for remote attackers to obtain administrative access via authorization requests involving (a) ActiveX, (b) a standalone client, or (c) unknown other vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-3612?
CVE-2013-3612 is rated as high severity due to the presence of hardcoded passwords allowing unauthorized administrative access.
How do I fix CVE-2013-3612?
To mitigate CVE-2013-3612, ensure to change the hardcoded passwords and secure the affected Dahua DVR appliances.
Which Dahua DVR models are affected by CVE-2013-3612?
CVE-2013-3612 affects multiple Dahua DVR models including DVR0404, DVR0804, DVR1604, DVR2100 series, and several others.
Can CVE-2013-3612 lead to a data breach?
Yes, CVE-2013-3612 can potentially lead to a data breach as it allows remote attackers access to sensitive camera feeds and device settings.
What actions should be taken after identifying CVE-2013-3612?
After identifying CVE-2013-3612, it is crucial to assess the security of your network, update the DVR firmware if available, and change default credentials.