CVE-2013-5754: Critical severity Dahuasecurity Dvr0404hd-a vulnerability
The authorization implementation on Dahua DVR appliances accepts a hash string representing the current date for the role of a master password, which makes it easier for remote attackers to obtain administrative access and change the administrator password via requests involving (1) ActiveX, (2) a standalone client, or (3) unspecified other vectors, a different vulnerability than CVE-2013-3612.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-5754?
The severity of CVE-2013-5754 is considered high due to the risk of unauthorized administrative access.
How do I fix CVE-2013-5754?
To fix CVE-2013-5754, update the Dahua DVR appliances to the latest firmware version provided by the manufacturer.
What types of devices are affected by CVE-2013-5754?
CVE-2013-5754 affects various Dahua DVR appliances, including models like DVR0404HD-A, DVR0804, and DVR1604HD-L.
What are the implications of CVE-2013-5754?
Exploitation of CVE-2013-5754 allows remote attackers to gain administrative control and modificar the administrator password.
How can I confirm if my device is vulnerable to CVE-2013-5754?
To confirm vulnerability, check your Dahua DVR model against the affected models listed in CVE-2013-5754 and review the firmware version.