ID

VAR-201601-0677


TITLE

Dahua camera onvif Protocol authentication is missing

Trust: 0.2

sources: IVD: 92a47388-1e6c-11e6-8415-000c29c12f8f

DESCRIPTION

Zhejiang Dahua Technology Co., Ltd. is a leading monitoring product supplier and solution service provider , Provide the world's leading series of video storage, front-end, display control and intelligent transportation products to the world. Dahua IPC-HF2100 Waiting for the camera onvif Agreement snapshot Interface access does not require authentication, allowing an attacker to directly access the live video image of the camera.

Trust: 0.2

sources: IVD: 92a47388-1e6c-11e6-8415-000c29c12f8f

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.2

sources: IVD: 92a47388-1e6c-11e6-8415-000c29c12f8f

AFFECTED PRODUCTS

vendor:dahuamodel: - scope:eqversion:;*

Trust: 0.2

sources: IVD: 92a47388-1e6c-11e6-8415-000c29c12f8f

CVSS

SEVERITY

CVSSV2

CVSSV3

IVD: 92a47388-1e6c-11e6-8415-000c29c12f8f
value: LOW

Trust: 0.2

IVD: 92a47388-1e6c-11e6-8415-000c29c12f8f
severity: LOW
baseScore: 3.3
vectorString: AV:A/AC:L/AU:N/C:P/I:N/A:N
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 6.5
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

sources: IVD: 92a47388-1e6c-11e6-8415-000c29c12f8f

TYPE

Permission permission and access control

Trust: 0.2

sources: IVD: 92a47388-1e6c-11e6-8415-000c29c12f8f

EXTERNAL IDS

db:IVDid:92A47388-1E6C-11E6-8415-000C29C12F8F

Trust: 0.2

sources: IVD: 92a47388-1e6c-11e6-8415-000c29c12f8f

SOURCES

db:IVDid:92a47388-1e6c-11e6-8415-000c29c12f8f

LAST UPDATE DATE

2022-05-04T09:05:04.637000+00:00


SOURCES UPDATE DATE


SOURCES RELEASE DATE

db:IVDid:92a47388-1e6c-11e6-8415-000c29c12f8fdate:2016-01-24T00:00:00