First published: Mon Nov 13 2017(Updated: )
Authentication vulnerability found in Dahua NVR models NVR50XX, NVR52XX, NVR54XX, NVR58XX with software before DH_NVR5xxx_Eng_P_V2.616.0000.0.R.20171102. Attacker could exploit this vulnerability to gain access to additional operations by means of forging json message.
Credit: cybersecurity@dahuatech.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dahuasecurity Nvr5464-16p-4ks2 Firmware | <dh_nvr5464_eng_p_v2.616.0000.0.r.20171102 | |
Dahuasecurity Nvr5464-16p-4ks2 | ||
Dahuasecurity Nvr5208-8p-4ks2 Firmware | <dh_nvr5208_eng_p_v2.616.0000.0.r.20171102 | |
Dahuasecurity Nvr5208-8p-4ks2 | ||
Dahuasecurity Nvr5432-16p-4ks2 Firmware | <dh_nvr5432_eng_p_v2.616.0000.0.r.20171102 | |
Dahuasecurity Nvr5432-16p-4ks2 | ||
Dahuasecurity Nvr5416-16p-4ks2 Firmware | <dh_nvr5416_eng_p_v2.616.0000.0.r.20171102 | |
Dahuasecurity Nvr5416-16p-4ks2 | ||
Dahuasecurity Nvr5464-4ks2 Firmware | <dh_nvr5464_eng_p_v2.616.0000.0.r.20171102 | |
Dahuasecurity Nvr5464-4ks2 | ||
Dahuasecurity Nvr5432-4ks2 Firmware | <dh_nvr5432_eng_p_v2.616.0000.0.r.20171102 | |
Dahuasecurity Nvr5432-4ks2 | ||
Dahuasecurity Nvr5416-4ks2 Firmware | <dh_nvr5416_eng_p_v2.616.0000.0.r.20171102 | |
Dahuasecurity Nvr5416-4ks2 | ||
Dahuasecurity Nvr5232-16p-4ks2 Firmware | <dh_nvr5232_eng_p_v2.616.0000.0.r.20171102 | |
Dahuasecurity Nvr5232-16p-4ks2 | ||
Dahuasecurity Nvr5216-16p-4ks2 Firmware | <dh_nvr5216_eng_p_v2.616.0000.0.r.20171102 | |
Dahuasecurity Nvr5216-16p-4ks2 | ||
Dahuasecurity Nvr5232-8p-4ks2 Firmware | <dh_nvr5232_eng_p_v2.616.0000.0.r.20171102 | |
Dahuasecurity Nvr5232-8p-4ks2 | ||
Dahuasecurity Nvr5216-8p-4ks2 Firmware | <dh_nvr5216_eng_p_v2.616.0000.0.r.20171102 | |
Dahuasecurity Nvr5216-8p-4ks2 | ||
Dahuasecurity Nvr5232-4ks2 Firmware | <dh_nvr5232_eng_p_v2.616.0000.0.r.20171102 | |
Dahuasecurity Nvr5232-4ks2 | ||
Dahuasecurity Nvr5216-4ks2 Firmware | <dh_nvr5216_eng_p_v2.616.0000.0.r.20171102 | |
Dahuasecurity Nvr5216-4ks2 | ||
Dahuasecurity Nvr5208-4ks2 Firmware | <dh_nvr5208_eng_p_v2.616.0000.0.r.20171102 | |
Dahuasecurity Nvr5208-4ks2 | ||
Dahuasecurity Nvr5816-4ks2 Firmware | <dh_nvr5816_eng_p_v2.616.0000.0.r.20171102 | |
Dahuasecurity Nvr5816-4ks2 | ||
Dahuasecurity Nvr5832-4ks2 Firmware | <dh_nvr5832_eng_p_v2.616.0000.0.r.20171102 | |
Dahuasecurity Nvr5832-4ks2 | ||
Dahuasecurity Nvr5864-4ks2 Firmware | <dh_nvr5864_eng_p_v2.616.0000.0.r.20171102 | |
Dahuasecurity Nvr5864-4ks2 | ||
Dahuasecurity Nvr5864-16p-4ks2 Firmware | <dh_nvr5864_eng_p_v2.616.0000.0.r.20171102 | |
Dahuasecurity Nvr5864-16p-4ks2 | ||
Dahuasecurity Nvr5832-16p-4ks2 Firmware | <dh_nvr5832_eng_p_v2.616.0000.0.r.20171102 | |
Dahuasecurity Nvr5832-16p-4ks2 | ||
Dahuasecurity Nvr5816-16p-4ks2 Firmware | <dh_nvr5816_eng_p_v2.616.0000.0.r.20171102 | |
Dahuasecurity Nvr5816-16p-4ks2 | ||
Dahuasecurity Nvr5424-24p-4ks2 Firmware | <dh_nvr5424_eng_p_v2.616.0000.0.r.20171102 | |
Dahuasecurity Nvr5424-24p-4ks2 | ||
Dahuasecurity Nvr5224-24p-4ks2 Firmware | <dh_nvr5224_eng_p_v2.616.0000.0.r.20171102 | |
Dahuasecurity Nvr5224-24p-4ks2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-9314 is high due to its potential impact on unauthorized access to operations on affected Dahua NVR models.
To fix CVE-2017-9314, update the firmware of affected Dahua NVR models to version DH_NVR5xxx_Eng_P_V2.616.0000.0.R.20171102 or later.
Affected Dahua NVR models include NVR50XX, NVR52XX, NVR54XX, and NVR58XX with software versions prior to DH_NVR5xxx_Eng_P_V2.616.0000.0.R.20171102.
CVE-2017-9314 is an authentication vulnerability that allows attackers to forge JSON messages and gain access to additional operations.
Yes, attackers can exploit CVE-2017-9314 by sending crafted JSON messages to manipulate operations on affected NVR devices.