PT-2024-1094 · D Link · D-Link Dcs-8300Lhv2

Ina Kheirkhah

+1

·

Published

2024-01-11

·

Updated

2024-11-25

·

CVE-2023-51629

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D-Link DCS-8300LHV2
Description The issue is related to the configuration of the ONVIF API in the D-Link DCS-8300LHV2 Wi-Fi camera, which is associated with weaknesses in the authentication procedure. This allows a remote attacker to bypass the authentication process. The specific flaw exists within the ONVIF API configuration, resulting from the use of a hardcoded PIN. An attacker can leverage this vulnerability to bypass authentication on the system.
Recommendations For D-Link DCS-8300LHV2, consider disabling the ONVIF API until a patch is available to prevent exploitation. Restrict access to the camera's network to minimize the risk of exploitation. Avoid using the hardcoded PIN in the ONVIF API configuration until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-00355
CVE-2023-51629
ZDI-24-049

Affected Products

D-Link Dcs-8300Lhv2