ID

VAR-201902-0162


CVE

CVE-2019-7389


TITLE

D-Link DIR-823G Vulnerability related to access control in device firmware

Trust: 0.8

sources: JVNDB: JVNDB-2019-001639

DESCRIPTION

An issue was discovered in /bin/goahead on D-Link DIR-823G devices with the firmware 1.02B03. There is incorrect access control allowing remote attackers to reset the router without authentication via the SetFactoryDefault HNAP API. Consequently, an attacker can achieve a denial-of-service attack without authentication. D-Link DIR-823G There is an access control vulnerability in the device firmware.Service operation interruption (DoS) There is a possibility of being put into a state. D-LinkDIR-823G is a wireless router from D-Link Corporation of Taiwan, China. D-Link DIR-823G is prone to a denial-of-service vulnerability. D-Link DIR-823G firmware 1.02B03 is vulnerable; other versions may also be affected

Trust: 2.61

sources: NVD: CVE-2019-7389 // JVNDB: JVNDB-2019-001639 // CNVD: CNVD-2019-24560 // BID: 106853 // VULHUB: VHN-158824 // VULMON: CVE-2019-7389

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2019-24560

AFFECTED PRODUCTS

vendor:dlinkmodel:dir-823gscope:eqversion:1.02b03

Trust: 1.0

vendor:d linkmodel:dir-823g 1.02b03scope: - version: -

Trust: 0.9

vendor:d linkmodel:dir-823gscope:eqversion:1.02b03

Trust: 0.8

sources: CNVD: CNVD-2019-24560 // BID: 106853 // JVNDB: JVNDB-2019-001639 // NVD: CVE-2019-7389

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2019-7389
value: HIGH

Trust: 1.0

NVD: CVE-2019-7389
value: HIGH

Trust: 0.8

CNVD: CNVD-2019-24560
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201902-051
value: HIGH

Trust: 0.6

VULHUB: VHN-158824
value: HIGH

Trust: 0.1

VULMON: CVE-2019-7389
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2019-7389
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

CNVD: CNVD-2019-24560
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-158824
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2019-7389
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2019-24560 // VULHUB: VHN-158824 // VULMON: CVE-2019-7389 // JVNDB: JVNDB-2019-001639 // CNNVD: CNNVD-201902-051 // NVD: CVE-2019-7389

PROBLEMTYPE DATA

problemtype:CWE-306

Trust: 1.1

problemtype:CWE-284

Trust: 0.9

sources: VULHUB: VHN-158824 // JVNDB: JVNDB-2019-001639 // NVD: CVE-2019-7389

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201902-051

TYPE

access control error

Trust: 0.6

sources: CNNVD: CNNVD-201902-051

CONFIGURATIONS

sources: JVNDB: JVNDB-2019-001639

PATCH

title:Top Pageurl:http://www.dlink.lt/en/

Trust: 0.8

sources: JVNDB: JVNDB-2019-001639

EXTERNAL IDS

db:NVDid:CVE-2019-7389

Trust: 3.5

db:BIDid:106853

Trust: 2.7

db:JVNDBid:JVNDB-2019-001639

Trust: 0.8

db:CNNVDid:CNNVD-201902-051

Trust: 0.7

db:CNVDid:CNVD-2019-24560

Trust: 0.6

db:VULHUBid:VHN-158824

Trust: 0.1

db:VULMONid:CVE-2019-7389

Trust: 0.1

sources: CNVD: CNVD-2019-24560 // VULHUB: VHN-158824 // VULMON: CVE-2019-7389 // BID: 106853 // JVNDB: JVNDB-2019-001639 // CNNVD: CNNVD-201902-051 // NVD: CVE-2019-7389

REFERENCES

url:https://github.com/leonw7/d-link/blob/master/vul_4.md

Trust: 2.9

url:http://www.securityfocus.com/bid/106853

Trust: 2.5

url:https://nvd.nist.gov/vuln/detail/cve-2019-7389

Trust: 2.0

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-7389

Trust: 0.8

url:https://github.com/leonw7/d-link/blob/master/vul_4.mdexploitthird party advisory

Trust: 0.6

url:http://www.securityfocus.com/bid/106853third party advisory

Trust: 0.6

url:http://www.d-link.com

Trust: 0.3

url:https://cwe.mitre.org/data/definitions/306.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: CNVD: CNVD-2019-24560 // VULHUB: VHN-158824 // VULMON: CVE-2019-7389 // BID: 106853 // JVNDB: JVNDB-2019-001639 // CNNVD: CNNVD-201902-051 // NVD: CVE-2019-7389

CREDITS

leonW7

Trust: 0.9

sources: BID: 106853 // CNNVD: CNNVD-201902-051

SOURCES

db:CNVDid:CNVD-2019-24560
db:VULHUBid:VHN-158824
db:VULMONid:CVE-2019-7389
db:BIDid:106853
db:JVNDBid:JVNDB-2019-001639
db:CNNVDid:CNNVD-201902-051
db:NVDid:CVE-2019-7389

LAST UPDATE DATE

2024-11-23T22:41:36.741000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2019-24560date:2019-07-29T00:00:00
db:VULHUBid:VHN-158824date:2020-08-24T00:00:00
db:VULMONid:CVE-2019-7389date:2020-08-24T00:00:00
db:BIDid:106853date:2019-02-04T00:00:00
db:JVNDBid:JVNDB-2019-001639date:2019-03-19T00:00:00
db:CNNVDid:CNNVD-201902-051date:2020-08-25T00:00:00
db:NVDid:CVE-2019-7389date:2024-11-21T04:48:07.693

SOURCES RELEASE DATE

db:CNVDid:CNVD-2019-24560date:2019-07-29T00:00:00
db:VULHUBid:VHN-158824date:2019-02-05T00:00:00
db:VULMONid:CVE-2019-7389date:2019-02-05T00:00:00
db:BIDid:106853date:2019-02-04T00:00:00
db:JVNDBid:JVNDB-2019-001639date:2019-03-19T00:00:00
db:CNNVDid:CNNVD-201902-051date:2019-02-04T00:00:00
db:NVDid:CVE-2019-7389date:2019-02-05T00:29:00.320