RSS   Vulnerabilities for 'Dvr3204lf-s'   RSS

2013-09-17
 
CVE-2013-5754

CWE-264
 

 
The authorization implementation on Dahua DVR appliances accepts a hash string representing the current date for the role of a master password, which makes it easier for remote attackers to obtain administrative access and change the administrator password via requests involving (1) ActiveX, (2) a standalone client, or (3) unspecified other vectors, a different vulnerability than CVE-2013-3612.

 
 
CVE-2013-3615

CWE-255
 

 
Dahua DVR appliances use a password-hash algorithm with a short hash length, which makes it easier for context-dependent attackers to discover cleartext passwords via a brute-force attack.

 
 
CVE-2013-3614

CWE-264
 

 
Dahua DVR appliances have a small value for the maximum password length, which makes it easier for remote attackers to obtain access via a brute-force attack.

 
 
CVE-2013-3613

CWE-287
 

 
Dahua DVR appliances do not properly restrict UPnP requests, which makes it easier for remote attackers to obtain access via vectors involving a replay attack against the TELNET port.

 
 
CVE-2013-3612

CWE-255
 

 
Dahua DVR appliances have a hardcoded password for (1) the root account and (2) an unspecified "backdoor" account, which makes it easier for remote attackers to obtain administrative access via authorization requests involving (a) ActiveX, (b) a standalone client, or (c) unknown other vectors.

 

 >>> Vendor: Dahuasecurity 119 Products
Dvr0404hd-a
Dvr0404hd-l
Dvr0404hd-s
Dvr0404hd-u
Dvr0404hf-a-e
Dvr0404hf-al-e
Dvr0404hf-s-e
Dvr0404hf-u-e
Dvr0804
Dvr0804hd-l
Dvr0804hd-s
Dvr0804hf-a-e
Dvr0804hf-al-e
Dvr0804hf-l-e
Dvr0804hf-s-e
Dvr0804hf-u-e
Dvr1604hd-l
Dvr1604hd-s
Dvr1604hf-a-e
Dvr1604hf-al-e
Dvr1604hf-l-e
Dvr1604hf-s-e
Dvr1604hf-u-e
Dvr2104c
Dvr2104h
Dvr2104hc
Dvr2104he
Dvr2108c
Dvr2108h
Dvr2108hc
Dvr2108he
Dvr2116c
Dvr2116h
Dvr2116hc
Dvr2116he
Dvr2404hf-s
Dvr2404lf-al
Dvr2404lf-s
Dvr3204hf-s
Dvr3204lf-al
Dvr3204lf-s
Dvr3224l
Dvr3232l
Dvr5104c
Dvr5104h
Dvr5104he
Dvr5108c
Dvr5108h
Dvr5108he
Dvr5116c
Dvr5116h
Dvr5116he
Dvr5204a
Dvr5204l
Dvr5208a
Dvr5208l
Dvr5216a
Dvr5216l
Dvr5404
Dvr5408
Dvr5416
Dvr5804
Dvr5808
Dvr5816
Dvr6404lf-s
Dvr firmware
Nvr firmware
Smartpss firmware
Camera firmware
Ip camera firmware
Dhi-hcvr58a32s-s2 firmware
Dh-ipc-hdw2xxx firmware
Dhi-hcvr51a04he-s3 firmware
Dh-nvr1xxx firmware
Dh-ipc-hdbw13a0sn firmware
Dh-ipc-hdw4xxx firmware
Dh-ipc-hfw1xxx firmware
Dh-hcvr4xxx firmware
Dh-ipc-hdbw23a0rn-zs firmware
Dh-sd6cxx firmware
Dh-ipc-hfw4xxx firmware
Dhi-hcvr51a08he-s3 firmware
Dh-hcvr5xxx firmware
Dh-ipc-hfw2xxx firmware
Dh-ipc-hdw1xxx firmware
Ipc-hdbw4x00 firmware
Ipc-hdbw5x00 firmware
Ipc-hdw4300s firmware
Ipc-hdw4x00 firmware
Ipc-hdw5x00 firmware
Ipc-hf5x00 firmware
Ipc-hfw4x00 firmware
Ipc-hfw5x00 firmware
Nvr11hs firmware
Dh-sd2xxxxx firmware
Dh-sd4xxxxx firmware
Dh-sd5xxxxx firmware
Dh-sd6xxxxx firmware
Ipc-ebw8xxx firmware
Ipc-hdbw1xxx firmware
See all Products for Vendor Dahuasecurity


Copyright 2018, cxsecurity.com

 

Back to Top