ID

VAR-201507-0711


TITLE

Design flaw in Dahua camera ddns setting

Trust: 0.6

sources: CNVD: CNVD-2015-04349

DESCRIPTION

Zhejiang Dahua Technology Co., Ltd. is a leading supplier of surveillance products and solution services, providing leading series of video storage, front-end, display control, and intelligent transportation products to the world. There is a security vulnerability in the Dahua camera ddns setting, allowing attackers to use the vulnerability to change and delete the dns record of the camera on the server at will, causing users to conduct phishing website attacks when using the domain name for camera access.

Trust: 0.6

sources: CNVD: CNVD-2015-04349

IOT TAXONOMY

category:['ICS', 'Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2015-04349

AFFECTED PRODUCTS

vendor: - model:dahua technology co. ltd.ipc-hf2100scope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2015-04349

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2015-04349
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2015-04349
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2015-04349

EXTERNAL IDS

db:CNVDid:CNVD-2015-04349

Trust: 0.6

sources: CNVD: CNVD-2015-04349

SOURCES

db:CNVDid:CNVD-2015-04349

LAST UPDATE DATE

2022-05-04T10:19:46.114000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2015-04349date:2015-07-08T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2015-04349date:2015-07-20T00:00:00