CVE-2017-9315: Critical severity dahua ipc-hfw1xxx vulnerability
Customer of Dahua IP camera or IP PTZ could submit relevant device information to receive a time limited temporary password from Dahua authorized dealer to reset the admin password. The algorithm used in this mechanism is potentially at risk of being compromised and subsequently utilized by attacker.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-9315?
CVE-2017-9315 is a vulnerability in Dahua IP cameras and IP PTZ (Pan-Tilt-Zoom) devices that allows an attacker to compromise the admin password reset mechanism.
What is the severity of CVE-2017-9315?
The severity of CVE-2017-9315 is critical with a severity score of 9.8.
How does the vulnerability in Dahua IP cameras and IP PTZ devices work?
The vulnerability allows an attacker to potentially compromise the algorithm used in the admin password reset mechanism.
Which versions of Dahua IP cameras and IP PTZ devices are affected by CVE-2017-9315?
Dahua IP cameras and IP PTZ devices with the following firmware are affected: Ipc-hfw1xxx, Ipc-hdw1xxx, Ipc-hdbw1xxx, Ipc-hfw2xxx, Ipc-hdw2xxx, Ipc-hdbw2xxx, Ipc-hfw4xxx, Ipc-hdw4xxx, Ipc-hdbw4xxx, Ipc-hf5xxx, Ipc-hfw5xxx, Ipc-hdw5xxx, Ipc-hdbw5xxx, Ipc-hf8xxx, Ipc-hfw8xxx, Ipc-hdbw8xxx, Ipc-ebw8xxx, Ipc-pfw8xxx, Dh-sd2xxxxx, Ipc-pdbw8xxx, Ipc-hum8xxx, Psd8xxxx, Dh-sd4xxxxx, Dh-sd5xxxxx, Dh-sd6xxxxx.
How can I fix the vulnerability in Dahua IP cameras and IP PTZ devices?
To fix the vulnerability, contact a Dahua authorized dealer to receive a time-limited temporary password and reset the admin password.