ID

VAR-201411-0549


TITLE

Multiple D-Link Products WPS-PIN Information Disclosure Vulnerability

Trust: 0.9

sources: CNVD: CNVD-2014-08110 // BID: 70903

DESCRIPTION

D-Link DIR-655, D-Link DIR-628 and D-Link DIR-615 are D-Link wireless router products. An information disclosure vulnerability exists in several D-Link products. An attacker could use this vulnerability to obtain sensitive information and gain unauthorized access to the device. The following products and versions are affected: D-Link DIR-655 0, D-Link DIR-628 0, D-Link DIR-615 4.13B01, D-Link DIR-615 0. Successfully exploiting this issue may lead to further attacks

Trust: 1.35

sources: CNVD: CNVD-2014-08110 // CNNVD: CNNVD-201411-076 // BID: 70903

IOT TAXONOMY

category:['IoT', 'Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2014-08110

AFFECTED PRODUCTS

vendor:d linkmodel:dir-615 4.13b01scope: - version: -

Trust: 0.9

vendor:d linkmodel:dir-615scope: - version: -

Trust: 0.6

vendor:d linkmodel:dir-628scope: - version: -

Trust: 0.6

vendor:d linkmodel:dir-655scope: - version: -

Trust: 0.6

vendor:d linkmodel:dir-857scope:eqversion:0

Trust: 0.3

vendor:d linkmodel:dir-855l 1.02b08scope: - version: -

Trust: 0.3

vendor:d linkmodel:dir-855scope:eqversion:0

Trust: 0.3

vendor:d linkmodel:dir-836lscope:eqversion:0

Trust: 0.3

vendor:d linkmodel:dir-835 1.04b04scope: - version: -

Trust: 0.3

vendor:d linkmodel:dir-835scope:eqversion:0

Trust: 0.3

vendor:d linkmodel:dir-827scope:eqversion:0

Trust: 0.3

vendor:d linkmodel:dir-826lscope:eqversion:0

Trust: 0.3

vendor:d linkmodel:dir-825scope:eqversion:0

Trust: 0.3

vendor:d linkmodel:dir-808lscope:eqversion:0

Trust: 0.3

vendor:d linkmodel:dir-657scope:eqversion:0

Trust: 0.3

vendor:d linkmodel:dir-655scope:eqversion:0

Trust: 0.3

vendor:d linkmodel:dir-651scope:eqversion:0

Trust: 0.3

vendor:d linkmodel:dir-636lscope:eqversion:0

Trust: 0.3

vendor:d linkmodel:dir-632scope:eqversion:0

Trust: 0.3

vendor:d linkmodel:dir-628scope:eqversion:0

Trust: 0.3

vendor:d linkmodel:dir-615 8.05b06scope: - version: -

Trust: 0.3

vendor:d linkmodel:dir-615scope:eqversion:5.10

Trust: 0.3

vendor:d linkmodel:dir-615scope:eqversion:4.13

Trust: 0.3

vendor:d linkmodel:dir-615scope:eqversion:0

Trust: 0.3

vendor:d linkmodel:dir-601scope:eqversion:0

Trust: 0.3

vendor:d linkmodel:dir-451scope:eqversion:0

Trust: 0.3

vendor:d linkmodel:dhp-1320scope:eqversion:0

Trust: 0.3

vendor:d linkmodel:dgl-4500scope:eqversion:0

Trust: 0.3

vendor:d linkmodel:dap-1555scope:eqversion:0

Trust: 0.3

vendor:d linkmodel:dap-1350scope:eqversion:1.14

Trust: 0.3

vendor:d linkmodel:dap-1350scope:eqversion:1.10

Trust: 0.3

vendor:d linkmodel:dap-1350scope:eqversion:0

Trust: 0.3

sources: CNVD: CNVD-2014-08110 // BID: 70903

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2014-08110
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2014-08110
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2014-08110

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201411-076

TYPE

information disclosure

Trust: 0.6

sources: CNNVD: CNNVD-201411-076

EXTERNAL IDS

db:BIDid:70903

Trust: 1.5

db:CNVDid:CNVD-2014-08110

Trust: 0.6

db:CNNVDid:CNNVD-201411-076

Trust: 0.6

db:DLINKid:SAP10047

Trust: 0.3

sources: CNVD: CNVD-2014-08110 // BID: 70903 // CNNVD: CNNVD-201411-076

REFERENCES

url:http://www.securityfocus.com/bid/70903

Trust: 1.2

url:http://www.dlink.com/

Trust: 0.3

url:http://securityadvisories.dlink.com/security/publication.aspx?name=sap10047

Trust: 0.3

sources: CNVD: CNVD-2014-08110 // BID: 70903 // CNNVD: CNNVD-201411-076

CREDITS

Craig of /dev/ttys0, and Hack-a-Day.

Trust: 0.9

sources: BID: 70903 // CNNVD: CNNVD-201411-076

SOURCES

db:CNVDid:CNVD-2014-08110
db:BIDid:70903
db:CNNVDid:CNNVD-201411-076

LAST UPDATE DATE

2022-05-17T01:55:54.496000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2014-08110date:2014-11-06T00:00:00
db:BIDid:70903date:2014-11-01T00:00:00
db:CNNVDid:CNNVD-201411-076date:2014-11-06T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2014-08110date:2014-11-06T00:00:00
db:BIDid:70903date:2014-11-01T00:00:00
db:CNNVDid:CNNVD-201411-076date:2014-11-06T00:00:00