CVE Intelligence
Skip to main content

CVE-2017-9316

CVE-2017-9316 Vulnerability Analysis & Exploit Intelligence

Firmware upgrade authentication bypass vulnerability was found in Dahua IPC-HDW4300S and some IP products. The vulnerability was caused by internal Debug function. This particular function was used for problem analysis and performance tuning during product development phase. It allowed the device to receive only specific data (one direction, no transmit) and therefore it was not involved in any instance of collecting user privacy data or allowing remote code execution.

Published Updated Sources: cvelistV5, dahua

Triage

Is it exploited, how likely is exploitation, what does it touch, and how severe do the scoring sources call it.

Exploitation

Unreported

no source claims exploitation

EPSS

2%

chance of exploitation in 30 days

Affects

dahua technologies

ipc_hdw4300s_nvr11hs_ipc_hfw4x00_ipc_hdw4x00_ipc_hdbw4x00_ipc_hf5x00_ipc_hfw5x00_ipc_hdw5x00_ipc_hdbw5x00_nvr11hs

CVSS base

Unscored

no source published a base score

Affected scope

The catalog records vendors and products as separate lists, not pairs, so which product belongs to which vendor is not something this page can say.

Products (1)

ipc hdw4300s nvr11hs ipc hfw4x00 ipc hdw4x00 ipc hdbw4x00 ipc hf5x00 ipc hfw5x00 ipc hdw5x00 ipc hdbw5x00 nvr11hs

References

1 on the record

Elsewhere on this site

Not in any source we poll

Listed rather than left blank: an empty field and an unmeasured one look identical on screen, and only one is a reason to look elsewhere.

  • No confirmed IOCs, IP addresses, domains, file hashes, or malware artifacts supplied.
  • No organization-specific asset inventory, compensating-control status, or patch deployment evidence supplied.
  • No exploit packet captures, log samples, or incident case IDs supplied.