A Use of Password Hash Instead of Password for Authentication issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX, DH-IPC-HFW1XXX, DH-IPC-HFW2XXX, DH-IPC-HFW4XXX, DH-SD6CXX, DH-NVR1XXX, DH-HCVR4XXX, DH-HCVR5XXX, DHI-HCVR51A04HE-S3, DHI-HCVR51A08HE-S3, and DHI-HCVR58A32S-S2 devices. The use of password hash instead of password for authentication vulnerability was identified, which could allow a malicious user to bypass authentication without obtaining the actual password.

Project Subscriptions

Vendors Products
Dahuasecurity Subscribe
Ddh-hcvr4xxx Subscribe
Dh-hcvr4xxx Firmware Subscribe
Dh-hcvr5xxx Subscribe
Dh-hcvr5xxx Firmware Subscribe
Dh-ipc-hdbw13a0sn Subscribe
Dh-ipc-hdbw13a0sn Firmware Subscribe
Dh-ipc-hdbw23a0rn-zs Subscribe
Dh-ipc-hdbw23a0rn-zs Firmware Subscribe
Dh-ipc-hdw1xxx Subscribe
Dh-ipc-hdw1xxx Firmware Subscribe
Dh-ipc-hdw2xxx Subscribe
Dh-ipc-hdw2xxx Firmware Subscribe
Dh-ipc-hdw4xxx Subscribe
Dh-ipc-hdw4xxx Firmware Subscribe
Dh-ipc-hfw1xxx Subscribe
Dh-ipc-hfw1xxx Firmware Subscribe
Dh-ipc-hfw2xxx Subscribe
Dh-ipc-hfw2xxx Firmware Subscribe
Dh-ipc-hfw4xxx Subscribe
Dh-ipc-hfw4xxx Firmware Subscribe
Dh-nvr1xxx Subscribe
Dh-nvr1xxx Firmware Subscribe
Dh-sd6cxx Subscribe
Dh-sd6cxx Firmware Subscribe
Dhi-hcvr51a04he-s3 Subscribe
Dhi-hcvr51a04he-s3 Firmware Subscribe
Dhi-hcvr51a08he-s3 Subscribe
Dhi-hcvr51a08he-s3 Firmware Subscribe
Dhi-hcvr58a32s-s2 Subscribe
Dhi-hcvr58a32s-s2 Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2017-16898 A Use of Password Hash Instead of Password for Authentication issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX, DH-IPC-HFW1XXX, DH-IPC-HFW2XXX, DH-IPC-HFW4XXX, DH-SD6CXX, DH-NVR1XXX, DH-HCVR4XXX, DH-HCVR5XXX, DHI-HCVR51A04HE-S3, DHI-HCVR51A08HE-S3, and DHI-HCVR58A32S-S2 devices. The use of password hash instead of password for authentication vulnerability was identified, which could allow a malicious user to bypass authentication without obtaining the actual password.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2024-08-05T16:19:29.227Z

Reserved: 2017-04-18T00:00:00

Link: CVE-2017-7927

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2017-05-06T00:29:00.460

Modified: 2025-04-20T01:37:25.860

Link: CVE-2017-7927

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses