Dvr0804hd L
Vendor:
First CVE: Sep 17, 2013 · Active for 12 years
5
Total CVEs
More Total CVEs than 79% of tracked products
5.0
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
9.0
Avg CVSS
Higher Avg CVSS than 84% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Dvr0804hd L over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 17, 2013
12 years ago
Most Recent CVE
Sep 17, 2013
4,697 days ago
CVE Severity & Scoring
Dvr0804hd L5 CVEs
100%
All CVEs353,240 CVEs
45%
40%
11%
High
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown5 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown5 (100.0%)
User Interaction
None0 (0.0%)
Unknown5 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown5 (100.0%)
Top CVEs
Signals from CVEs in this product scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-3612HIGH Dahua DVR appliances have a hardcoded password for (1) the root account and (2) an unspecified "backdoor" account, which makes it easier for remote attackers to obtain administrati | Sep 17, 2013 | 10.0 | 39 | NO | YES |
CVE-2013-3614HIGH Dahua DVR appliances have a small value for the maximum password length, which makes it easier for remote attackers to obtain access via a brute-force attack. | Sep 17, 2013 | 9.3 | 36 | NO | YES |
CVE-2013-3615HIGH Dahua DVR appliances use a password-hash algorithm with a short hash length, which makes it easier for context-dependent attackers to discover cleartext passwords via a brute-force | Sep 17, 2013 | 7.8 | 32 | NO | YES |
CVE-2013-3613HIGH Dahua DVR appliances do not properly restrict UPnP requests, which makes it easier for remote attackers to obtain access via vectors involving a replay attack against the TELNET po | Sep 17, 2013 | 7.8 | 31 | NO | YES |
CVE-2013-5754HIGH The authorization implementation on Dahua DVR appliances accepts a hash string representing the current date for the role of a master password, which makes it easier for remote att | Sep 17, 2013 | 10.0 | 30 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (5 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
80.0% of CVEs· 91st percentile
Social Chatter
Signals from CVEs in this product scope (5 CVEs).
Media Mentions
Signals from CVEs in this product scope (5 CVEs).
Top CNAs Publishing CVEs For Dvr0804hd L
Top CWEs
Versions
No cataloged versions.