Intrusion Prevention

Dahua.IP.Camera.Unauthorized.File.Access.Information.Disclosure

Description

This indicates an attack attempting to exploit an Information Disclosure vulnerability in Dahua IP Camera.
This issue is caused by an error in the vulnerable software when handling malicious requests. It may allow remote attackers to access potentially sensitive files.

Affected Products

DH-IPC-HDW23A0RN-ZS
DH-IPC-HDBW23A0RN-ZS
DH-IPC-HDBW13A0SN
DH-IPC-HDW13A0SN
DH-IPC-HFW13A0SN-W
DH-IPC-HDBW13A0SN
DH-IPC-HDW13A0SN
DH-IPC-HFW13A0SN-W
DHI-HCVR51A04HE-S3
DHI-HCVR51A08HE-S3
DHI-HCVR58A32S-S2

Impact

Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems.

Recommended Actions

Apply the most recent upgrade or patch from the vendor.
http://us.dahuasecurity.com/en/us/Security-Bulletin_030617.php#none

CVE References

CVE-2017-6343