CVE-2017-7927

UnknownEPSS 36.75%

Last modified

CVE-2017-7927 is a vulnerability of currently unknown severity. A Use of Password Hash Instead of Password for Authentication issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX, DH-IPC-HFW1XXX, DH-IPC-HFW2XXX, DH-IPC-HFW4XXX, DH-SD6CXX, DH-NVR1XXX, DH-HCVR4XXX, DH-HCVR5XXX, DHI-HCVR51A04HE-S3, DHI-HCVR51A08HE-S3, and DHI-HCVR58A32S-S2 devices. The use of password hash instead of password for authentication vulnerability was identified, which could allow a malicious user to bypass authentication without obtaining the actual password.. EPSS estimates a 36.75% chance of exploitation in the next 30 days.

Description

A Use of Password Hash Instead of Password for Authentication issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX, DH-IPC-HFW1XXX, DH-IPC-HFW2XXX, DH-IPC-HFW4XXX, DH-SD6CXX, DH-NVR1XXX, DH-HCVR4XXX, DH-HCVR5XXX, DHI-HCVR51A04HE-S3, DHI-HCVR51A08HE-S3, and DHI-HCVR58A32S-S2 devices. The use of password hash instead of password for authentication vulnerability was identified, which could allow a malicious user to bypass authentication without obtaining the actual password.

Metrics

EPSS Probability
36.75%

98.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
DahuasecurityDh-Ipc-Hdbw23a0rn-Zs FirmwareAll versions
DahuasecurityDh-Ipc-Hdbw13a0sn FirmwareAll versions
DahuasecurityDh-Ipc-Hdw1xxx FirmwareAll versions
DahuasecurityDh-Ipc-Hdw2xxx FirmwareAll versions
DahuasecurityDh-Ipc-Hdw4xxx FirmwareAll versions
DahuasecurityDh-Ipc-Hfw1xxx FirmwareAll versions
DahuasecurityDh-Ipc-Hfw2xxx FirmwareAll versions
DahuasecurityDh-Ipc-Hfw4xxx FirmwareAll versions
DahuasecurityDh-Sd6cxx FirmwareAll versions
DahuasecurityDh-Nvr1xxx FirmwareAll versions
DahuasecurityDh-Hcvr4xxx FirmwareAll versions
DahuasecurityDh-Hcvr5xxx FirmwareAll versions
DahuasecurityDhi-Hcvr51a04he-S3 FirmwareAll versions
DahuasecurityDhi-Hcvr51a08he-S3 FirmwareAll versions
DahuasecurityDhi-Hcvr58a32s-S2 FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2017-7927?
A Use of Password Hash Instead of Password for Authentication issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX, DH-IPC-HFW1XXX, DH-IPC-HFW2XXX, DH-IPC-HFW4XXX, DH-SD6CXX, DH-NVR1XXX, DH-HCVR4XXX, DH-HCVR5XXX, DHI-HCVR51A04HE-S3, DHI-HCVR51A08HE-S3, and DHI-HCVR58A32S-S2 devices. The use of password hash instead of password for authentication vulnerability was identified, which could allow a malicious user to bypass authentication without obtaining the actual password.
How severe is CVE-2017-7927?
Severity scoring for CVE-2017-7927 is pending analysis. The EPSS model estimates a 36.75% probability of exploitation in the next 30 days.
How do I fix CVE-2017-7927?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2017-7927?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST