CVE-2017-7925

UnknownEPSS 52.06%

Last modified

CVE-2017-7925 is a vulnerability of currently unknown severity. A Password in Configuration File issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX, DH-IPC-HFW1XXX, DH-IPC-HFW2XXX, DH-IPC-HFW4XXX, DH-SD6CXX, DH-NVR1XXX, DH-HCVR4XXX, DH-HCVR5XXX, DHI-HCVR51A04HE-S3, DHI-HCVR51A08HE-S3, and DHI-HCVR58A32S-S2 devices. The password in configuration file vulnerability was identified, which could lead to a malicious user assuming the identity of a privileged user and gaining access to sensitive information.. EPSS estimates a 52.06% chance of exploitation in the next 30 days.

Description

A Password in Configuration File issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX, DH-IPC-HFW1XXX, DH-IPC-HFW2XXX, DH-IPC-HFW4XXX, DH-SD6CXX, DH-NVR1XXX, DH-HCVR4XXX, DH-HCVR5XXX, DHI-HCVR51A04HE-S3, DHI-HCVR51A08HE-S3, and DHI-HCVR58A32S-S2 devices. The password in configuration file vulnerability was identified, which could lead to a malicious user assuming the identity of a privileged user and gaining access to sensitive information.

Metrics

EPSS Probability
52.06%

98.8th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
DahuasecurityDh-Ipc-Hdbw23a0rn-Zs FirmwareAll versions
DahuasecurityDh-Ipc-Hdbw13a0sn FirmwareAll versions
DahuasecurityDh-Ipc-Hdw1xxx FirmwareAll versions
DahuasecurityDh-Ipc-Hdw2xxx FirmwareAll versions
DahuasecurityDh-Ipc-Hdw4xxx FirmwareAll versions
DahuasecurityDh-Ipc-Hfw1xxx FirmwareAll versions
DahuasecurityDh-Ipc-Hfw2xxx FirmwareAll versions
DahuasecurityDh-Ipc-Hfw4xxx FirmwareAll versions
DahuasecurityDh-Sd6cxx FirmwareAll versions
DahuasecurityDh-Nvr1xxx FirmwareAll versions
DahuasecurityDh-Hcvr4xxx FirmwareAll versions
DahuasecurityDh-Hcvr5xxx FirmwareAll versions
DahuasecurityDhi-Hcvr51a04he-S3 FirmwareAll versions
DahuasecurityDhi-Hcvr51a08he-S3 FirmwareAll versions
DahuasecurityDhi-Hcvr58a32s-S2 FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2017-7925?
A Password in Configuration File issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX, DH-IPC-HFW1XXX, DH-IPC-HFW2XXX, DH-IPC-HFW4XXX, DH-SD6CXX, DH-NVR1XXX, DH-HCVR4XXX, DH-HCVR5XXX, DHI-HCVR51A04HE-S3, DHI-HCVR51A08HE-S3, and DHI-HCVR58A32S-S2 devices. The password in configuration file vulnerability was identified, which could lead to a malicious user assuming the identity of a privileged user and gaining access to sensitive information.
How severe is CVE-2017-7925?
Severity scoring for CVE-2017-7925 is pending analysis. The EPSS model estimates a 52.06% probability of exploitation in the next 30 days.
How do I fix CVE-2017-7925?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2017-7925?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST