CVE-2017-9317: Dahuasecurity Ipc-HDBW4XXX Firmware
High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.
Privilege escalation vulnerability found in some Dahua IP devices. Attacker in possession of low privilege account can gain access to credential information of high privilege account and further obtain device information or attack the device.
Affected products
- Dahuasecurity Ipc-HDBW4XXX Firmware: before 2.622.0000000.18.r.20171110 (fixed in 2.622.0000000.18.r.20171110); before 2.621.0000.28.r.20170912 (fixed in 2.621.0000.28.r.20170912)
- Dahuasecurity Ipc-HDBW5XXX Firmware: before 2.622.0000000.18.r.20171110 (fixed in 2.622.0000000.18.r.20171110); before 2.621.0000.28.r.20170912 (fixed in 2.621.0000.28.r.20170912)
- Dahuasecurity XVR5X04 Firmware: before 3.218.0000002.1.r.171229 (fixed in 3.218.0000002.1.r.171229)
- Dahuasecurity XVR5X08 Firmware: before 3.218.0000002.1.r.171229 (fixed in 3.218.0000002.1.r.171229)
- Dahuasecurity XVR5X16 Firmware: before 3.218.0000002.1.r.171229 (fixed in 3.218.0000002.1.r.171229)
- Dahuasecurity XVR7X16 Firmware: before 3.218.0000002.1.r.171229 (fixed in 3.218.0000002.1.r.171229)
Published 2018-05-23. Last modified 2026-06-17.