PT-2024-1094 · D Link · D-Link Dcs-8300Lhv2
Ina Kheirkhah
+1
·
Published
2024-01-11
·
Updated
2024-11-25
·
CVE-2023-51629
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
D-Link DCS-8300LHV2
Description
The issue is related to the configuration of the ONVIF API in the D-Link DCS-8300LHV2 Wi-Fi camera, which is associated with weaknesses in the authentication procedure. This allows a remote attacker to bypass the authentication process. The specific flaw exists within the ONVIF API configuration, resulting from the use of a hardcoded PIN. An attacker can leverage this vulnerability to bypass authentication on the system.
Recommendations
For D-Link DCS-8300LHV2, consider disabling the ONVIF API until a patch is available to prevent exploitation.
Restrict access to the camera's network to minimize the risk of exploitation.
Avoid using the hardcoded PIN in the ONVIF API configuration until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Authentication
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
D-Link Dcs-8300Lhv2