PT-2021-23316 · D Link · D-Link Dcs-932L+1

Azad Mustafa

+1

·

Published

2021-09-24

·

Updated

2024-08-04

·

CVE-2021-41504

CVSS v3.1

8.0

High

VectorAV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D-Link DCS-5000L version 1.05 and older D-Link DCS-932L version 2.17 and older
Description An Elevated Privileges issue exists due to the use of digest-authentication for the devices command interface, potentially allowing malicious users on the LAN to access the device and compromise its configuration. This issue only affects products that are no longer supported by the maintainer.
Recommendations For D-Link DCS-5000L version 1.05 and older, consider disabling the digest-authentication for the devices command interface as a temporary workaround to minimize the risk of exploitation. For D-Link DCS-932L version 2.17 and older, restrict access to the devices command interface until a solution is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2021-41504

Affected Products

D-Link Dcs-5000L
D-Link Dcs-932L