CVE Intelligence
Skip to main content

CVE-2017-9317

CVE-2017-9317 Vulnerability Analysis & Exploit Intelligence

Privilege escalation vulnerability found in some Dahua IP devices. Attacker in possession of low privilege account can gain access to credential information of high privilege account and further obtain device information or attack the device.

Published Updated Sources: cvelistV5, dahua

Triage

Is it exploited, how likely is exploitation, what does it touch, and how severe do the scoring sources call it.

Exploitation

Unreported

no source claims exploitation

EPSS

1%

chance of exploitation in 30 days

Affects

dahua technologies

xvr_5x04_xvr_5x08_xvr_5x16_xvr_7x16_ipc_hdbw4xxx_ipc_hdbw5xxx

CVSS base

Unscored

no source published a base score

Affected scope

The catalog records vendors and products as separate lists, not pairs, so which product belongs to which vendor is not something this page can say.

Products (1)

xvr 5x04 xvr 5x08 xvr 5x16 xvr 7x16 ipc hdbw4xxx ipc hdbw5xxx

References

1 on the record

Elsewhere on this site

Not in any source we poll

Listed rather than left blank: an empty field and an unmeasured one look identical on screen, and only one is a reason to look elsewhere.

  • No confirmed IOCs, IP addresses, domains, file hashes, or malware artifacts supplied.
  • No organization-specific asset inventory, compensating-control status, or patch deployment evidence supplied.
  • No exploit packet captures, log samples, or incident case IDs supplied.