A Use of Password Hash Instead of Password for Authentication issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX, DH-IPC-HFW1XXX, DH-IPC-HFW2XXX, DH-IPC-HFW4XXX, DH-SD6CXX, DH-NVR1XXX, DH-HCVR4XXX, DH-HCVR5XXX, DHI-HCVR51A04HE-S3, DHI-HCVR51A08HE-S3, and DHI-HCVR58A32S-S2 devices. The use of password hash instead of password for authentication vulnerability was identified, which could allow a malicious user to bypass authentication without obtaining the actual password.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Dahuasecurity
Subscribe
|
Ddh-hcvr4xxx
Subscribe
Dh-hcvr4xxx Firmware
Subscribe
Dh-hcvr5xxx
Subscribe
Dh-hcvr5xxx Firmware
Subscribe
Dh-ipc-hdbw13a0sn
Subscribe
Dh-ipc-hdbw13a0sn Firmware
Subscribe
Dh-ipc-hdbw23a0rn-zs
Subscribe
Dh-ipc-hdbw23a0rn-zs Firmware
Subscribe
Dh-ipc-hdw1xxx
Subscribe
Dh-ipc-hdw1xxx Firmware
Subscribe
Dh-ipc-hdw2xxx
Subscribe
Dh-ipc-hdw2xxx Firmware
Subscribe
Dh-ipc-hdw4xxx
Subscribe
Dh-ipc-hdw4xxx Firmware
Subscribe
Dh-ipc-hfw1xxx
Subscribe
Dh-ipc-hfw1xxx Firmware
Subscribe
Dh-ipc-hfw2xxx
Subscribe
Dh-ipc-hfw2xxx Firmware
Subscribe
Dh-ipc-hfw4xxx
Subscribe
Dh-ipc-hfw4xxx Firmware
Subscribe
Dh-nvr1xxx
Subscribe
Dh-nvr1xxx Firmware
Subscribe
Dh-sd6cxx
Subscribe
Dh-sd6cxx Firmware
Subscribe
Dhi-hcvr51a04he-s3
Subscribe
Dhi-hcvr51a04he-s3 Firmware
Subscribe
Dhi-hcvr51a08he-s3
Subscribe
Dhi-hcvr51a08he-s3 Firmware
Subscribe
Dhi-hcvr58a32s-s2
Subscribe
Dhi-hcvr58a32s-s2 Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-16898 | A Use of Password Hash Instead of Password for Authentication issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX, DH-IPC-HFW1XXX, DH-IPC-HFW2XXX, DH-IPC-HFW4XXX, DH-SD6CXX, DH-NVR1XXX, DH-HCVR4XXX, DH-HCVR5XXX, DHI-HCVR51A04HE-S3, DHI-HCVR51A08HE-S3, and DHI-HCVR58A32S-S2 devices. The use of password hash instead of password for authentication vulnerability was identified, which could allow a malicious user to bypass authentication without obtaining the actual password. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2024-08-05T16:19:29.227Z
Reserved: 2017-04-18T00:00:00
Link: CVE-2017-7927
No data.
Status : Deferred
Published: 2017-05-06T00:29:00.460
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-7927
No data.
OpenCVE Enrichment
No data.
EUVD