MEDIUM
D-Link DNS-320 Web Management Interface discovery.cgi information disclosure
Published Sep 5, 2024
6.9
MEDIUMCVSS 4.0
EPSS 1.85%
Description
A vulnerability, which was classified as problematic, was found in D-Link DNS-320 2.02b01. This affects an unknown part of the file /cgi-bin/discovery.cgi of the component Web Management Interface. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. Vendor was contacted early and confirmed that the product is end-of-life. It should be retired and replaced.
Affected products
-
- Version 2.02b01StatusaffectedConstraints-
- Version
AND
- 2.02b01
-
- Version 2.02b01StatusaffectedConstraints-
- Version
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (7)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-49195 Advisory
- https://github.com/leetsun/IoT-Vuls/tree/main/Dlink-dns320/4 exploitThird Party Advisory
- https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10383 relatedNot Applicable
- https://vuldb.com/?ctiid.276627 signaturepermissions-requiredPermissions Required
- https://vuldb.com/?id.276627 vdb-entryThird Party Advisory
- https://vuldb.com/?submit.401300 third-party-advisoryThird Party Advisory
- https://www.dlink.com/ product
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-49195 | Advisory | |
| https://github.com/leetsun/IoT-Vuls/tree/main/Dlink-dns320/4 | exploitThird Party Advisory | |
| https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10383 | relatedNot Applicable | |
| https://vuldb.com/?ctiid.276627 | signaturepermissions-requiredPermissions Required | |
| https://vuldb.com/?id.276627 | vdb-entryThird Party Advisory | |
| https://vuldb.com/?submit.401300 | third-party-advisoryThird Party Advisory | |
| https://www.dlink.com/ | product |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Sep 5, 2024
Updated Sep 5, 2024
Reserved Sep 5, 2024
Link CVE-2024-8461
CISA Vulnrichment
Updated Sep 5, 2024
ENISA EUVD
EUVD-2024-49195 Assigner VulDB
Published Sep 5, 2024
Updated Sep 5, 2024
Exploited since n/a
Link EUVD-2024-49195