PT-2021-23315 · D Link · Dcs-932L+1

Azad Mustafa

+1

·

Published

2021-09-24

·

Updated

2024-08-04

·

CVE-2021-41503

CVSS v3.1

8.0

High

VectorAV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DCS-5000L version 1.05 and earlier DCS-932L version 2.17 and earlier
Description The issue is related to incorrect access control, allowing malicious users on the LAN to access the device due to the use of basic authentication for the devices' command interface. This may compromise the camera's configuration. The vulnerability only affects products that are no longer supported by the maintainer.
Recommendations For DCS-5000L version 1.05 and earlier, consider disabling the basic authentication for the devices' command interface until a patch is available. For DCS-932L version 2.17 and earlier, restrict access to the command interface to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2021-41503

Affected Products

Dcs-5000L
Dcs-932L