CVE-2017-9317: High severity dahuasecurity xvr-5x16 firmware vulnerability
Privilege escalation vulnerability found in some Dahua IP devices. Attacker in possession of low privilege account can gain access to credential information of high privilege account and further obtain device information or attack the device.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2017-9317?
CVE-2017-9317 is a privilege escalation vulnerability found in some Dahua IP devices.
How severe is CVE-2017-9317?
CVE-2017-9317 has a severity rating of 8.8 (high).
Which Dahua IP devices are affected by CVE-2017-9317?
Dahuasecurity Xvr5x16 Firmware (up to version 3.218.0000002.1.r.171229), Dahuasecurity Xvr5x08 Firmware (up to version 3.218.0000002.1.r.171229), Dahuasecurity Xvr5x04 Firmware (up to version 3.218.0000002.1.r.171229), Dahuasecurity Xvr7x16 Firmware (up to version 3.218.0000002.1.r.171229), Dahuasecurity Ipc-hdbw4xxx Firmware (up to version 2.622.0000000.18.r.20171110), Dahuasecurity Ipc-hdbw4xxx Firmware (up to version 2.621.0000.28.r.20170912), Dahuasecurity Ipc-hdbw5xxx Firmware (up to version 2.622.0000000.18.r.20171110), Dahuasecurity Ipc-hdbw5xxx Firmware (up to version 2.621.0000.28.r.20170912).
What can an attacker do with CVE-2017-9317?
An attacker in possession of a low privilege account can gain access to credential information of a high privilege account and further obtain device information or attack the device.
How can I fix CVE-2017-9317?
To fix CVE-2017-9317, upgrade to a version of the Dahua IP device firmware that is not vulnerable.