CVE-2017-6343: High severity Dahuasecurity Camera Firmware vulnerability
The web interface on Dahua DHI-HCVR7216A-S3 devices with NVR Firmware 3.210.0001.10 2016-06-06, Camera Firmware 2.400.0000.28.R 2016-03-29, and SmartPSS Software 1.16.1 2017-01-19 allows remote attackers to obtain login access by leveraging knowledge of the MD5 Admin Hash without knowledge of the corresponding password, a different vulnerability than CVE-2013-6117.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6343?
CVE-2017-6343 is classified as a high severity vulnerability due to its potential for remote exploitation.
How do I fix CVE-2017-6343?
To mitigate CVE-2017-6343, update the Dahua firmware to the latest version provided by the manufacturer.
What devices are affected by CVE-2017-6343?
CVE-2017-6343 affects Dahua DHI-HCVR7216A-S3 devices with specific firmware versions of NVR, Camera, and SmartPSS.
What type of attack does CVE-2017-6343 enable?
CVE-2017-6343 allows remote attackers to gain unauthorized login access using an MD5 hashed admin password.
Is there a known exploit for CVE-2017-6343?
Yes, CVE-2017-6343 is known to be actively exploited in the wild, targeting unpatched devices.