CVE Vulnerabilities

CVE-2013-6117

Improper Authentication

Published: Jul 11, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io minimus.io echohq.com

Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive information including user credentials, change user passwords, clear log files, and perform other actions via a request to TCP port 37777.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Dvr_firmware Dahuasecurity 2.608.0000.0 (including) 2.608.0000.0 (including)
Dvr_firmware Dahuasecurity 2.608.gv00.0 (including) 2.608.gv00.0 (including)

Potential Mitigations

References