PT-2019-16079 · Netis · Netis Dl4323

Published

2019-12-29

·

Updated

2020-08-24

·

CVE-2019-20074

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Netis DL4323 (affected versions not specified)
Description The issue allows any user role to access sensitive information, including user passwords and the FTP password, by visiting the "form2saveConf.cgi" page.
Recommendations For Netis DL4323 devices, restrict access to the "form2saveConf.cgi" page until a patch is available.

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-20074

Affected Products

Netis Dl4323