CVE-2013-5754
Last modified
CVE-2013-5754 is a vulnerability of currently unknown severity. The authorization implementation on Dahua DVR appliances accepts a hash string representing the current date for the role of a master password, which makes it easier for remote attackers to obtain administrative access and change the administrator password via requests involving (1) ActiveX, (2) a standalone client, or (3) unspecified other vectors, a different vulnerability than CVE-2013-3612.. EPSS estimates a 2.48% chance of exploitation in the next 30 days.
Description
The authorization implementation on Dahua DVR appliances accepts a hash string representing the current date for the role of a master password, which makes it easier for remote attackers to obtain administrative access and change the administrator password via requests involving (1) ActiveX, (2) a standalone client, or (3) unspecified other vectors, a different vulnerability than CVE-2013-3612.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dahuasecurity | Dvr0404hd-A | All versions |
| Dahuasecurity | Dvr0404hd-L | All versions |
| Dahuasecurity | Dvr0404hd-S | All versions |
| Dahuasecurity | Dvr0404hd-U | All versions |
| Dahuasecurity | Dvr0404hf-A-E | All versions |
| Dahuasecurity | Dvr0404hf-Al-E | All versions |
| Dahuasecurity | Dvr0404hf-S-E | All versions |
| Dahuasecurity | Dvr0404hf-U-E | All versions |
| Dahuasecurity | Dvr0804 | All versions |
| Dahuasecurity | Dvr0804hd-L | All versions |
| Dahuasecurity | Dvr0804hd-S | All versions |
| Dahuasecurity | Dvr0804hf-A-E | All versions |
| Dahuasecurity | Dvr0804hf-Al-E | All versions |
| Dahuasecurity | Dvr0804hf-L-E | All versions |
| Dahuasecurity | Dvr0804hf-S-E | All versions |
| Dahuasecurity | Dvr0804hf-U-E | All versions |
| Dahuasecurity | Dvr1604hd-L | All versions |
| Dahuasecurity | Dvr1604hd-S | All versions |
| Dahuasecurity | Dvr1604hf-A-E | All versions |
| Dahuasecurity | Dvr1604hf-Al-E | All versions |
| Dahuasecurity | Dvr1604hf-L-E | All versions |
| Dahuasecurity | Dvr1604hf-S-E | All versions |
| Dahuasecurity | Dvr1604hf-U-E | All versions |
| Dahuasecurity | Dvr2104c | All versions |
| Dahuasecurity | Dvr2104h | All versions |
| Dahuasecurity | Dvr2104hc | All versions |
| Dahuasecurity | Dvr2104he | All versions |
| Dahuasecurity | Dvr2108c | All versions |
| Dahuasecurity | Dvr2108h | All versions |
| Dahuasecurity | Dvr2108hc | All versions |
| Dahuasecurity | Dvr2108he | All versions |
| Dahuasecurity | Dvr2116c | All versions |
| Dahuasecurity | Dvr2116h | All versions |
| Dahuasecurity | Dvr2116hc | All versions |
| Dahuasecurity | Dvr2116he | All versions |
| Dahuasecurity | Dvr2404hf-S | All versions |
| Dahuasecurity | Dvr2404lf-Al | All versions |
| Dahuasecurity | Dvr2404lf-S | All versions |
| Dahuasecurity | Dvr3204hf-S | All versions |
| Dahuasecurity | Dvr3204lf-Al | All versions |
| Dahuasecurity | Dvr3204lf-S | All versions |
| Dahuasecurity | Dvr3224l | All versions |
| Dahuasecurity | Dvr3232l | All versions |
| Dahuasecurity | Dvr5104c | All versions |
| Dahuasecurity | Dvr5104h | All versions |
| Dahuasecurity | Dvr5104he | All versions |
| Dahuasecurity | Dvr5108c | All versions |
| Dahuasecurity | Dvr5108h | All versions |
| Dahuasecurity | Dvr5108he | All versions |
| Dahuasecurity | Dvr5116c | All versions |
Showing 50 of 65 affected configurations. See NVD for the full list.
References
- http://www.kb.cert.org/vuls/id/800094US Government Resource
- http://www.kb.cert.org/vuls/id/800094US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-5754?
How severe is CVE-2013-5754?
How do I fix CVE-2013-5754?
Are you affected by CVE-2013-5754?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
