CVE-2017-3223
Dahua
- Published
- 24 July 2018
- Last modified
- 17 June 2026
- CVSS
- 9.8 v3.0
- Severity
- critical
- EPSS
- 5.3% (92th pct)
- CISA KEV
- Not listed
- NVD status
- Modified
- Weaknesses
- CWE-121, CWE-119
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
Dahua IP camera products using firmware versions prior to V2.400.0000.14.R.20170713 include a version of the Sonia web interface that may be vulnerable to a stack buffer overflow. Dahua IP camera products include an application known as Sonia (/usr/bin/sonia) that provides the web interface and other services for controlling the IP camera remotely. Versions of Sonia included in firmware versions prior to DH_IPC-Consumer-Zi-Themis_Eng_P_V2.408.0000.11.R.20170621 do not validate input data length for the 'password' field of the web interface. A remote, unauthenticated attacker may submit a crafted POST request to the IP camera's Sonia web interface that may lead to out-of-bounds memory operations and loss of availability or remote code execution. The issue was originally identified by the researcher in firmware version DH_IPC-HX1X2X-Themis_EngSpnFrn_N_V2.400.0000.30.R.20160803.
Exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalogue as of 2026.09.04. The catalogue records confirmed public exploitation. Absence from it does not establish that exploitation has not occurred. EPSS models a 5.3% probability of exploitation activity in the next 30 days, placing it in the top decile of all scored CVEs.
Affected products
| Product | Vendor | Type | Versions named |
|---|---|---|---|
| IP Camera | Dahua | IP camera | 3.200.0001.6, < 2.400.0000.14.r.20170713, < dh_ipc-ack-themis_eng_p_v2.400.0000.14.r.20170713.bin |
References
- http://www.securityfocus.com/bid/99620 third-party
- https://www.kb.cert.org/vuls/id/547255 third-party
- http://www.securityfocus.com/bid/99620 third-party
- https://www.kb.cert.org/vuls/id/547255 third-party
Record assembled from NVD, CISA KEV 2026.09.04 and FIRST EPSS 2026-09-04. Affected products are those NVD's CPE configuration names that fall inside this site's scope; a CVE may affect products outside it.