ICSA-17-124-02
·
Published 2017-05-04
·
View on CISA ICS-CERT ↗
Dahua Technology Co., Ltd Digital Video Recorders and IP Cameras
CVSS 9.8
CRITICAL
Risk Summary
ATTENTION: Remotely exploitable/low skill level to exploit. Public exploits are available.
CVEs (2)
Remediations
- Dahua has released updated firmware to mitigate these vulnerabilities.
- Updated software can be obtained from Dahua technical support or an authorized Dahua distributor.
- In addition, Dahua released the following security notifications for users:
- Cyber Vulnerability Affecting Certain Dahua IP Cameras and Recorders (March 6)
- Cybersecurity Statement - March 6, 2017
- Cybersecurity Vulnerability Update - March 8, 2017
- Cyber Vulnerability Affecting Certain Dahua IP Cameras and Recorders (April 3)
- Dahua's original notification specifies 11 affected models, but after initial testing, Dahua has identified additional series and models in the following security notification:
- Security Notification DHCC-201703-01
Affected Vendors
Dahua Technology Co, Ltd
Affected Products (15)
Dahua Technology Co, Ltd
·
Digital Video Recorders and IP Cameras
DH-IPC-HDBW23A0RN-ZS,
Dahua Technology Co, Ltd
·
Digital Video Recorders and IP Cameras
DH-IPC-HDBW13A0SN,
Dahua Technology Co, Ltd
·
Digital Video Recorders and IP Cameras
DH-IPC-HDW1XXX,
Dahua Technology Co, Ltd
·
Digital Video Recorders and IP Cameras
DH-IPC-HDW2XXX,
Dahua Technology Co, Ltd
·
Digital Video Recorders and IP Cameras
DH-IPC-HDW4XXX,
Dahua Technology Co, Ltd
·
Digital Video Recorders and IP Cameras
DH-IPC-HFW1XXX,
Dahua Technology Co, Ltd
·
Digital Video Recorders and IP Cameras
DH-IPC-HFW2XXX,
Dahua Technology Co, Ltd
·
Digital Video Recorders and IP Cameras
DH-IPC-HFW4XXX,
Dahua Technology Co, Ltd
·
Digital Video Recorders and IP Cameras
DH-SD6CXX,
Dahua Technology Co, Ltd
·
Digital Video Recorders and IP Cameras
DH-NVR1XXX,
Dahua Technology Co, Ltd
·
Digital Video Recorders and IP Cameras
DH-HCVR4XXX, and
Dahua Technology Co, Ltd
·
Digital Video Recorders and IP Cameras
DH-HCVR5XXX
Dahua Technology Co, Ltd
·
Digital Video Recorders and IP Cameras
DHI-HCVR51A04HE-S3,
Dahua Technology Co, Ltd
·
Digital Video Recorders and IP Cameras
DHI-HCVR51A08HE-S3, and
Dahua Technology Co, Ltd
·
Digital Video Recorders and IP Cameras
DHI-HCVR58A32S-S2
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more