PT-2021-23316 · D Link · D-Link Dcs-932L+1
Azad Mustafa
+1
·
Published
2021-09-24
·
Updated
2024-08-04
·
CVE-2021-41504
CVSS v3.1
8.0
High
| Vector | AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
D-Link DCS-5000L version 1.05 and older
D-Link DCS-932L version 2.17 and older
Description
An Elevated Privileges issue exists due to the use of digest-authentication for the devices command interface, potentially allowing malicious users on the LAN to access the device and compromise its configuration. This issue only affects products that are no longer supported by the maintainer.
Recommendations
For D-Link DCS-5000L version 1.05 and older, consider disabling the digest-authentication for the devices command interface as a temporary workaround to minimize the risk of exploitation.
For D-Link DCS-932L version 2.17 and older, restrict access to the devices command interface until a solution is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
D-Link Dcs-5000L
D-Link Dcs-932L