Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-7698

Опубликовано: 05 мар. 2018
Источник: nvd
CVSS3: 8.1
CVSS2: 4.3
EPSS Низкий

Описание

An issue was discovered in D-Link mydlink+ 3.8.5 build 259 for DCS-933L 1.05.04 and DCS-934L 1.05.04 devices. The mydlink+ app sends the username and password for connected D-Link cameras (such as DCS-933L and DCS-934L) unencrypted from the app to the camera, allowing attackers to obtain these credentials and gain control of the camera including the ability to view the camera's stream and make changes without the user's knowledge.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:d-link:mydlink\+:3.8.5:*:*:*:*:*:*:*

EPSS

Процентиль: 53%
0.00298
Низкий

8.1 High

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-522

Связанные уязвимости

CVSS3: 8.1
github
больше 3 лет назад

An issue was discovered in D-Link mydlink+ 3.8.5 build 259 for DCS-933L 1.05.04 and DCS-934L 1.05.04 devices. The mydlink+ app sends the username and password for connected D-Link cameras (such as DCS-933L and DCS-934L) unencrypted from the app to the camera, allowing attackers to obtain these credentials and gain control of the camera including the ability to view the camera's stream and make changes without the user's knowledge.

EPSS

Процентиль: 53%
0.00298
Низкий

8.1 High

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-522