Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-41503

Опубликовано: 24 сент. 2021
Источник: nvd
CVSS3: 8
CVSS2: 5.2
EPSS Низкий

Описание

DCS-5000L v1.05 and DCS-932L v2.17 and older are affecged by Incorrect Acess Control. The use of the basic authentication for the devices command interface allows attack vectors that may compromise the cameras configuration and allow malicious users on the LAN to access the device. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:dlink:dcs-932l_firmware:*:*:*:*:*:*:*:*
Версия до 2.17 (включая)
cpe:2.3:h:dlink:dcs-932l:-:*:*:*:*:*:*:*
Конфигурация 2

Одновременно

cpe:2.3:o:d-link:dcs-5000l_firmware:1.05:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dcs-5000l:-:*:*:*:*:*:*:*

EPSS

Процентиль: 62%
0.0043
Низкий

8 High

CVSS3

5.2 Medium

CVSS2

Дефекты

CWE-287
CWE-287

Связанные уязвимости

CVSS3: 8
github
больше 3 лет назад

** UNSUPPORTED WHEN ASSIGNED ** DCS-5000L v1.05 and DCS-932L v2.17 and older are affecged by Incorrect Acess Control. The use of the basic authentication for the devices command interface allows attack vectors that may compromise the cameras configuration and allow malicious users on the LAN to access the device. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

EPSS

Процентиль: 62%
0.0043
Низкий

8 High

CVSS3

5.2 Medium

CVSS2

Дефекты

CWE-287
CWE-287