PatchSiren cyber security CVE debrief
CVE-2017-6341 Dahuasecurity CVE debrief
CVE-2017-6341 describes a cleartext credential exposure issue in several Dahua products. According to the NVD record, affected versions include DHI-HCVR7216A-S3 NVR firmware 3.210.0001.10, camera firmware 2.400.0000.28.R, and SmartPSS 1.16.1. The issue affects responses from the Web Page, Mobile Application, and Desktop Application interfaces, allowing an attacker with suitable network access to recover sensitive information by sniffing traffic. This is classified as CWE-319 (Cleartext Transmission of Sensitive Information).
- Vendor
- Dahuasecurity
- Product
- Unknown
- CVSS
- MEDIUM 5.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-27
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-27
- Advisory updated
- 2026-05-13
Who should care
Organizations running the listed Dahua NVR, camera firmware, or SmartPSS versions should care, especially if devices are reachable over untrusted networks or traffic can be observed by other hosts on the same segment.
Technical summary
NVD maps this issue to CVSS v3.0 AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N and CWE-319. The vulnerable behavior is that passwords are sent in cleartext in responses associated with the Web Page, Mobile Application, and Desktop Application interfaces. The practical risk is credential disclosure to a network attacker capable of sniffing traffic. The affected CPE entries in the record include Dahua camera firmware 2.400.0000.28.R, NVR firmware 3.210.0001.10, and SmartPSS 1.16.1.
Defensive priority
Medium. Credential exposure is serious because captured passwords can be reused, but the NVD vector indicates no direct integrity or availability impact and requires network sniffing conditions.
Recommended defensive actions
- Identify whether any Dahua devices or SmartPSS installations match the affected versions listed in NVD.
- Apply vendor-provided updates or replacements for the affected firmware/software where available.
- Treat credentials that may have traversed these interfaces as potentially exposed and rotate them if exposure is suspected.
- Limit management-plane access to trusted networks and administrative hosts only.
- Monitor for unexpected authentication attempts or reuse of compromised credentials.
- Avoid exposing these interfaces across networks where passive sniffing is possible.
Evidence notes
This debrief is grounded in the supplied NVD record and referenced advisories. The NVD metadata explicitly lists the affected Dahua firmware/software versions, the CVSS v3.0 vector, and CWE-319. The source corpus also links third-party advisories from SecurityFocus, nullku7’s write-up, and a related Twitter post. No exploit code or reproduction details were used.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-6341 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-6341
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-6341 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-6341
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://nullku7.github.io/stuff/exposure/dahua/2017/02/24/dahua-nvr.html
[email protected] - Third Party Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://twitter.com/null_ku7/status/835649185168838657
[email protected] - Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.