ID

VAR-201309-0168


CVE

CVE-2013-3613


TITLE

Dahua Security DVRs contain multiple vulnerabilities

Trust: 0.8

sources: CERT/CC: VU#800094

DESCRIPTION

Dahua DVR appliances do not properly restrict UPnP requests, which makes it easier for remote attackers to obtain access via vectors involving a replay attack against the TELNET port. Digital video recorders (DVR) produced by Dahua Technology Co., Ltd. contain multiple vulnerabilities that could allow a remote attacker to gain privileged access to the devices. Dahua Security DVR Appliances accept UPnP requests from external untrusted devices, which can cause the telnet port of the DVR application device to be automatically redirected and accessed by external entities. These default conditions allow external attackers to detect the device and use the built-in account to authenticate. Access the device. An attacker can exploit this issue to bypass the authentication mechanism and perform unauthorized actions. This may aid in further attacks

Trust: 3.15

sources: NVD: CVE-2013-3613 // CERT/CC: VU#800094 // JVNDB: JVNDB-2013-004184 // CNVD: CNVD-2013-13179 // BID: 62402

IOT TAXONOMY

category:['IoT', 'Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2013-13179

AFFECTED PRODUCTS

vendor:dahuasecuritymodel:dvr2104hcscope:eqversion: -

Trust: 1.6

vendor:dahuasecuritymodel:dvr2116hescope:eqversion: -

Trust: 1.6

vendor:dahuasecuritymodel:dvr5216lscope:eqversion: -

Trust: 1.6

vendor:dahuasecuritymodel:dvr2104cscope:eqversion: -

Trust: 1.6

vendor:dahuasecuritymodel:dvr2108hescope:eqversion: -

Trust: 1.6

vendor:dahuasecuritymodel:dvr5204ascope:eqversion: -

Trust: 1.6

vendor:dahuasecuritymodel:dvr2116cscope:eqversion: -

Trust: 1.6

vendor:dahuasecuritymodel:dvr2116hcscope:eqversion: -

Trust: 1.6

vendor:dahuasecuritymodel:dvr2108cscope:eqversion: -

Trust: 1.6

vendor:dahuasecuritymodel:dvr2108hcscope:eqversion: -

Trust: 1.6

vendor:dahuasecuritymodel:dvr0804hf-s-escope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr5104hescope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr0804hf-u-escope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr5116cscope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr0404hd-ascope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr0804hd-lscope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr0804hf-al-escope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr0404hf-a-escope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr0404hd-sscope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr5204lscope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr5116hescope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr2108hscope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr1604hf-l-escope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr5108hescope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr2116hscope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr0804hf-l-escope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr5208ascope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr0804scope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr6404lf-sscope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr2404lf-alscope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr0404hd-uscope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr5104hscope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr5108cscope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr5216ascope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr5808scope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr1604hf-a-escope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr5816scope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr1604hf-s-escope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr2404hf-sscope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr0404hf-u-escope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr5104cscope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr0404hd-lscope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr5404scope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr1604hf-al-escope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr0404hf-s-escope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr5408scope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr5108hscope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr5804scope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr2104hscope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr1604hf-u-escope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr0804hf-a-escope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr3204lf-sscope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr2104hescope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr5208lscope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr2404lf-sscope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr3204hf-sscope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr5416scope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr0804hd-sscope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr3204lf-alscope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr5116hscope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr0404hf-al-escope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr1604hd-lscope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr3232lscope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr1604hd-sscope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:dvr3224lscope:eqversion: -

Trust: 1.0

vendor:dahuamodel:dvr0404hd-ascope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr0404hd-lscope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr0404hd-sscope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr0404hd-uscope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr0404hf-a-escope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr0404hf-al-escope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr0404hf-s-escope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr0404hf-u-escope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr0804scope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr0804hd-lscope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr0804hd-sscope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr0804hf-a-escope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr0804hf-al-escope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr0804hf-l-escope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr0804hf-s-escope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr0804hf-u-escope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr1604hd-lscope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr1604hd-sscope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr1604hf-a-escope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr1604hf-al-escope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr1604hf-l-escope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr1604hf-s-escope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr1604hf-u-escope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr2104cscope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr2104hscope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr2104hcscope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr2104hescope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr2108cscope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr2108hscope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr2108hcscope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr2108hescope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr2116cscope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr2116hscope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr2116hcscope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr2116hescope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr2404hf-sscope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr2404lf-alscope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr2404lf-sscope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr3204hf-sscope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr3204lf-alscope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr3204lf-sscope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr3224lscope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr3232lscope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr5104cscope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr5104hscope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr5104hescope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr5108cscope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr5108hscope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr5108hescope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr5116cscope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr5116hscope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr5116hescope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr5204ascope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr5204lscope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr5208ascope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr5208lscope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr5216ascope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr5216lscope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr5404scope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr5408scope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr5416scope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr5804scope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr5808scope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr5816scope: - version: -

Trust: 0.8

vendor:dahuamodel:dvr6404lf-sscope: - version: -

Trust: 0.8

vendor:dahuamodel:security dvr appliancesscope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2013-13179 // JVNDB: JVNDB-2013-004184 // CNNVD: CNNVD-201309-263 // NVD: CVE-2013-3613

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2013-3613
value: HIGH

Trust: 1.0

NVD: CVE-2013-3613
value: HIGH

Trust: 0.8

CNVD: CNVD-2013-13179
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201309-263
value: HIGH

Trust: 0.6

nvd@nist.gov: CVE-2013-3613
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:C/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2013-13179
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2013-13179 // JVNDB: JVNDB-2013-004184 // CNNVD: CNNVD-201309-263 // NVD: CVE-2013-3613

PROBLEMTYPE DATA

problemtype:CWE-287

Trust: 1.8

sources: JVNDB: JVNDB-2013-004184 // NVD: CVE-2013-3613

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201309-263

TYPE

authorization issue

Trust: 0.6

sources: CNNVD: CNNVD-201309-263

CONFIGURATIONS

sources: JVNDB: JVNDB-2013-004184

PATCH

title:Top Pageurl:http://www.dahuasecurity.com/

Trust: 0.8

sources: JVNDB: JVNDB-2013-004184

EXTERNAL IDS

db:CERT/CCid:VU#800094

Trust: 4.1

db:NVDid:CVE-2013-3613

Trust: 3.3

db:BIDid:62402

Trust: 1.5

db:JVNid:JVNVU99181254

Trust: 0.8

db:JVNDBid:JVNDB-2013-004184

Trust: 0.8

db:CNVDid:CNVD-2013-13179

Trust: 0.6

db:CNNVDid:CNNVD-201309-263

Trust: 0.6

sources: CERT/CC: VU#800094 // CNVD: CNVD-2013-13179 // BID: 62402 // JVNDB: JVNDB-2013-004184 // CNNVD: CNNVD-201309-263 // NVD: CVE-2013-3613

REFERENCES

url:http://www.kb.cert.org/vuls/id/800094

Trust: 3.3

url:about vulnerability notes

Trust: 0.8

url:contact us about this vulnerability

Trust: 0.8

url:provide a vendor statement

Trust: 0.8

url:http://www.dahuasecurity.com/

Trust: 0.8

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2013-3613

Trust: 0.8

url:http://jvn.jp/cert/jvnvu99181254

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2013-3613

Trust: 0.8

url:http://www.securityfocus.com/bid/62402

Trust: 0.6

url:http://www.dahuasecurity.com/products_category/dvr-2.html

Trust: 0.3

sources: CERT/CC: VU#800094 // CNVD: CNVD-2013-13179 // BID: 62402 // JVNDB: JVNDB-2013-004184 // CNNVD: CNNVD-201309-263 // NVD: CVE-2013-3613

CREDITS

Andrey Bezborodov, Kirill Ermakov, Alexander Raspopov, and Dmitry Sklyarov of Positive Technologies.

Trust: 0.9

sources: BID: 62402 // CNNVD: CNNVD-201309-263

SOURCES

db:CERT/CCid:VU#800094
db:CNVDid:CNVD-2013-13179
db:BIDid:62402
db:JVNDBid:JVNDB-2013-004184
db:CNNVDid:CNNVD-201309-263
db:NVDid:CVE-2013-3613

LAST UPDATE DATE

2025-04-11T23:04:04.757000+00:00


SOURCES UPDATE DATE

db:CERT/CCid:VU#800094date:2013-12-04T00:00:00
db:CNVDid:CNVD-2013-13179date:2013-09-23T00:00:00
db:BIDid:62402date:2013-09-13T00:00:00
db:JVNDBid:JVNDB-2013-004184date:2013-09-19T00:00:00
db:CNNVDid:CNNVD-201309-263date:2017-05-08T00:00:00
db:NVDid:CVE-2013-3613date:2025-04-11T00:51:21.963

SOURCES RELEASE DATE

db:CERT/CCid:VU#800094date:2013-09-13T00:00:00
db:CNVDid:CNVD-2013-13179date:2013-09-23T00:00:00
db:BIDid:62402date:2013-09-13T00:00:00
db:JVNDBid:JVNDB-2013-004184date:2013-09-19T00:00:00
db:CNNVDid:CNNVD-201309-263date:2013-09-22T00:00:00
db:NVDid:CVE-2013-3613date:2013-09-17T12:04:24.757