CVE-2013-6117
Estado: ModificadaAlta (7.5)—
Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive information including user credentials, change user passwords, clear log files, and perform other actions via a request to TCP port 37777.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 70%
- Percentil entre todas las CVEs puntuadas: 99
- Fecha de la puntuación: 3/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-287
Referencias
- http://blog.depthsecurity.com/2013/11/dahua-dvr-authentication-bypass-cve.html
- http://packetstormsecurity.com/files/124022/Dahua-DVR-Authentication-Bypass.html
- http://seclists.org/bugtraq/2013/Nov/62
- http://www.exploit-db.com/exploits/29673
- http://www.osvdb.org/99783
- http://blog.depthsecurity.com/2013/11/dahua-dvr-authentication-bypass-cve.html
- http://packetstormsecurity.com/files/124022/Dahua-DVR-Authentication-Bypass.html
- http://seclists.org/bugtraq/2013/Nov/62
- http://www.exploit-db.com/exploits/29673
- http://www.osvdb.org/99783
JSON original (NVD)
Mostrar
{
"id": "CVE-2013-6117",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2014-07-11T19:55:02.673",
"references": [
{
"url": "http://blog.depthsecurity.com/2013/11/dahua-dvr-authentication-bypass-cve.html",
"source": "cve@mitre.org"
},
{
"url": "http://packetstormsecurity.com/files/124022/Dahua-DVR-Authentication-Bypass.html",
"source": "cve@mitre.org"
},
{
"url": "http://seclists.org/bugtraq/2013/Nov/62",
"source": "cve@mitre.org"
},
{
"url": "http://www.exploit-db.com/exploits/29673",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/99783",
"source": "cve@mitre.org"
},
{
"url": "http://blog.depthsecurity.com/2013/11/dahua-dvr-authentication-bypass-cve.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://packetstormsecurity.com/files/124022/Dahua-DVR-Authentication-Bypass.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://seclists.org/bugtraq/2013/Nov/62",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.exploit-db.com/exploits/29673",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/99783",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-287"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive information including user credentials, change user passwords, clear log files, and perform other actions via a request to TCP port 37777."
},
{
"lang": "es",
"value": "Dahua DVR 2.608.0000.0 y 2.608.GV00.0 permite a atacantes remotos evadir la autenticación y obtener información sensible que incluye las credenciales de usarios, cambiar las contraseñas de usuarios, limpiar los ficheros de registros y realizar otras acciones a través de una solicitud al puerto TCP 37777."
}
],
"lastModified": "2026-06-16T23:59:59.393",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:dahuasecurity:dvr_firmware:2.608.0000.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3632E5BD-37BA-45BE-AD77-9B69BF741334"
},
{
"criteria": "cpe:2.3:o:dahuasecurity:dvr_firmware:2.608.gv00.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "ADC44E39-10BF-409D-84E3-F66736429647"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}