ID

VAR-201301-0476


TITLE

D-Link DCS Cameras Authentication Bypass Vulnerability

Trust: 0.9

sources: BID: 57611 // CNNVD: CNNVD-201301-569

DESCRIPTION

D-Link DCS is a camera device product. D-Link DCS web cameras allow unauthenticated attackers to remotely obtain configuration information for the device. An attacker can submit a configuration file by submitting the following URL: http://<device IP address>/frame/GetConfig. Attackers may exploit this issue to execute arbitrary commands, gain unauthorized access, or bypass intended security restrictions. Other attacks may also be possible. The following versions are vulnerable: DCS-930L version 1.04 DCS-932L version 1.02 http://drupal.org/node/207891

Trust: 0.99

sources: CNVD: CNVD-2013-00643 // BID: 57611 // IVD: 89c78a0c-1f39-11e6-abef-000c29c66e3d

IOT TAXONOMY

category:['IoT', 'ICS', 'Network device']sub_category: -

Trust: 0.6

category:['ICS']sub_category: -

Trust: 0.2

sources: IVD: 89c78a0c-1f39-11e6-abef-000c29c66e3d // CNVD: CNVD-2013-00643

AFFECTED PRODUCTS

vendor:d linkmodel:dcs-932l versionscope:eqversion:1.02

Trust: 0.8

vendor:d linkmodel:dcs-930l versionscope:eqversion:1.04

Trust: 0.6

vendor:d linkmodel:dcs-930l versionscope:eqversion:1.04*

Trust: 0.2

sources: IVD: 89c78a0c-1f39-11e6-abef-000c29c66e3d // CNVD: CNVD-2013-00643

CVSS

SEVERITY

CVSSV2

CVSSV3

IVD: 89c78a0c-1f39-11e6-abef-000c29c66e3d
value: MEDIUM

Trust: 0.2

IVD: 89c78a0c-1f39-11e6-abef-000c29c66e3d
severity: NONE
baseScore: NONE
vectorString: NONE
accessVector: NONE
accessComplexity: NONE
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: UNKNOWN

Trust: 0.2

sources: IVD: 89c78a0c-1f39-11e6-abef-000c29c66e3d

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201301-569

TYPE

permissions and access control

Trust: 0.6

sources: CNNVD: CNNVD-201301-569

PATCH

title:D-Link DCS Cameras verifies patches that bypass the vulnerabilityurl:https://www.cnvd.org.cn/patchinfo/show/31173

Trust: 0.6

sources: CNVD: CNVD-2013-00643

EXTERNAL IDS

db:BIDid:57611

Trust: 1.5

db:CNVDid:CNVD-2013-00643

Trust: 0.8

db:CNNVDid:CNNVD-201301-569

Trust: 0.6

db:IVDid:89C78A0C-1F39-11E6-ABEF-000C29C66E3D

Trust: 0.2

sources: IVD: 89c78a0c-1f39-11e6-abef-000c29c66e3d // CNVD: CNVD-2013-00643 // BID: 57611 // CNNVD: CNNVD-201301-569

REFERENCES

url:http://seclists.org/bugtraq/2013/jan/119

Trust: 0.6

url:http://www.securityfocus.com/bid/57611

Trust: 0.6

sources: CNVD: CNVD-2013-00643 // CNNVD: CNNVD-201301-569

CREDITS

Roberto Paleari

Trust: 0.9

sources: BID: 57611 // CNNVD: CNNVD-201301-569

SOURCES

db:IVDid:89c78a0c-1f39-11e6-abef-000c29c66e3d
db:CNVDid:CNVD-2013-00643
db:BIDid:57611
db:CNNVDid:CNNVD-201301-569

LAST UPDATE DATE

2022-05-17T01:43:28.756000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2013-00643date:2013-02-01T00:00:00
db:BIDid:57611date:2013-01-29T00:00:00
db:CNNVDid:CNNVD-201301-569date:2013-01-31T00:00:00

SOURCES RELEASE DATE

db:IVDid:89c78a0c-1f39-11e6-abef-000c29c66e3ddate:2013-02-01T00:00:00
db:CNVDid:CNVD-2013-00643date:2013-02-01T00:00:00
db:BIDid:57611date:2013-01-29T00:00:00
db:CNNVDid:CNNVD-201301-569date:2013-01-31T00:00:00