CVE Vulnerabilities

CVE-2013-3613

Improper Authentication

Published: Sep 17, 2013 | Modified: Sep 17, 2013
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:C/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Dahua DVR appliances do not properly restrict UPnP requests, which makes it easier for remote attackers to obtain access via vectors involving a replay attack against the TELNET port.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Dvr0404hd-a Dahuasecurity - (including) - (including)
Dvr0404hd-l Dahuasecurity - (including) - (including)
Dvr0404hd-s Dahuasecurity - (including) - (including)
Dvr0404hd-u Dahuasecurity - (including) - (including)
Dvr0404hf-a-e Dahuasecurity - (including) - (including)
Dvr0404hf-al-e Dahuasecurity - (including) - (including)
Dvr0404hf-s-e Dahuasecurity - (including) - (including)
Dvr0404hf-u-e Dahuasecurity - (including) - (including)
Dvr0804 Dahuasecurity - (including) - (including)
Dvr0804hd-l Dahuasecurity - (including) - (including)
Dvr0804hd-s Dahuasecurity - (including) - (including)
Dvr0804hf-a-e Dahuasecurity - (including) - (including)
Dvr0804hf-al-e Dahuasecurity - (including) - (including)
Dvr0804hf-l-e Dahuasecurity - (including) - (including)
Dvr0804hf-s-e Dahuasecurity - (including) - (including)
Dvr0804hf-u-e Dahuasecurity - (including) - (including)
Dvr1604hd-l Dahuasecurity - (including) - (including)
Dvr1604hd-s Dahuasecurity - (including) - (including)
Dvr1604hf-a-e Dahuasecurity - (including) - (including)
Dvr1604hf-al-e Dahuasecurity - (including) - (including)
Dvr1604hf-l-e Dahuasecurity - (including) - (including)
Dvr1604hf-s-e Dahuasecurity - (including) - (including)
Dvr1604hf-u-e Dahuasecurity - (including) - (including)
Dvr2104c Dahuasecurity - (including) - (including)
Dvr2104h Dahuasecurity - (including) - (including)
Dvr2104hc Dahuasecurity - (including) - (including)
Dvr2104he Dahuasecurity - (including) - (including)
Dvr2108c Dahuasecurity - (including) - (including)
Dvr2108h Dahuasecurity - (including) - (including)
Dvr2108hc Dahuasecurity - (including) - (including)
Dvr2108he Dahuasecurity - (including) - (including)
Dvr2116c Dahuasecurity - (including) - (including)
Dvr2116h Dahuasecurity - (including) - (including)
Dvr2116hc Dahuasecurity - (including) - (including)
Dvr2116he Dahuasecurity - (including) - (including)
Dvr2404hf-s Dahuasecurity - (including) - (including)
Dvr2404lf-al Dahuasecurity - (including) - (including)
Dvr2404lf-s Dahuasecurity - (including) - (including)
Dvr3204hf-s Dahuasecurity - (including) - (including)
Dvr3204lf-al Dahuasecurity - (including) - (including)
Dvr3204lf-s Dahuasecurity - (including) - (including)
Dvr3224l Dahuasecurity - (including) - (including)
Dvr3232l Dahuasecurity - (including) - (including)
Dvr5104c Dahuasecurity - (including) - (including)
Dvr5104h Dahuasecurity - (including) - (including)
Dvr5104he Dahuasecurity - (including) - (including)
Dvr5108c Dahuasecurity - (including) - (including)
Dvr5108h Dahuasecurity - (including) - (including)
Dvr5108he Dahuasecurity - (including) - (including)
Dvr5116c Dahuasecurity - (including) - (including)
Dvr5116h Dahuasecurity - (including) - (including)
Dvr5116he Dahuasecurity - (including) - (including)
Dvr5204a Dahuasecurity - (including) - (including)
Dvr5204l Dahuasecurity - (including) - (including)
Dvr5208a Dahuasecurity - (including) - (including)
Dvr5208l Dahuasecurity - (including) - (including)
Dvr5216a Dahuasecurity - (including) - (including)
Dvr5216l Dahuasecurity - (including) - (including)
Dvr5404 Dahuasecurity - (including) - (including)
Dvr5408 Dahuasecurity - (including) - (including)
Dvr5416 Dahuasecurity - (including) - (including)
Dvr5804 Dahuasecurity - (including) - (including)
Dvr5808 Dahuasecurity - (including) - (including)
Dvr5816 Dahuasecurity - (including) - (including)
Dvr6404lf-s Dahuasecurity - (including) - (including)

Potential Mitigations

References