ID

VAR-202007-0677


CVE

CVE-2020-15896


TITLE

D-Link DAP-1522 Authentication vulnerabilities in devices

Trust: 0.8

sources: JVNDB: JVNDB-2020-008695

DESCRIPTION

An authentication-bypass issue was discovered on D-Link DAP-1522 devices 1.4x before 1.10b04Beta02. There exist a few pages that are directly accessible by any unauthorized user, e.g., logout.php and login.php. This occurs because of checking the value of NO_NEED_AUTH. If the value of NO_NEED_AUTH is 1, the user has direct access to the webpage without any authentication. By appending a query string NO_NEED_AUTH with the value of 1 to any protected URL, any unauthorized user can access the application directly, as demonstrated by bsc_lan.php?NO_NEED_AUTH=1. D-Link DAP-1522 There is an authentication vulnerability in the device.Information may be obtained. D-Link DAP-1522 is a wireless access point product of D-Link, Taiwan. D-Link DAP-1522 1.10b04Beta02 has a security vulnerability in the 1.4x version. An attacker can use this vulnerability to bypass authentication and directly access the application

Trust: 2.16

sources: NVD: CVE-2020-15896 // JVNDB: JVNDB-2020-008695 // CNVD: CNVD-2020-46227

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2020-46227

AFFECTED PRODUCTS

vendor:dlinkmodel:dap-1522scope:eqversion:1.42

Trust: 1.0

vendor:dlinkmodel:dap-1522scope:eqversion:1.41

Trust: 1.0

vendor:d linkmodel:dap-1522scope: - version: -

Trust: 0.8

vendor:d linkmodel:dap-1522 1.4*,<1.10b04beta02scope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2020-46227 // JVNDB: JVNDB-2020-008695 // NVD: CVE-2020-15896

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-15896
value: HIGH

Trust: 1.0

NVD: JVNDB-2020-008695
value: HIGH

Trust: 0.8

CNVD: CNVD-2020-46227
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-202007-1379
value: HIGH

Trust: 0.6

nvd@nist.gov: CVE-2020-15896
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

NVD: JVNDB-2020-008695
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

CNVD: CNVD-2020-46227
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2020-15896
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.1

Trust: 1.0

NVD: JVNDB-2020-008695
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2020-46227 // JVNDB: JVNDB-2020-008695 // CNNVD: CNNVD-202007-1379 // NVD: CVE-2020-15896

PROBLEMTYPE DATA

problemtype:CWE-287

Trust: 1.8

sources: JVNDB: JVNDB-2020-008695 // NVD: CVE-2020-15896

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202007-1379

TYPE

authorization issue

Trust: 0.6

sources: CNNVD: CNNVD-202007-1379

CONFIGURATIONS

sources: JVNDB: JVNDB-2020-008695

PATCH

title:DAP-1520 Rev. Ax FW 1.10B04 / DAP-1522 Rev. Ax FW 1.42 / DIR-816L Rev. Bx FW 2.06.B09 :: End of Support Recommendation for Disclosed Vulnerabiltieisurl:https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10169

Trust: 0.8

title:Patch for D-Link DAP-1522 authentication bypass vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/230431

Trust: 0.6

sources: CNVD: CNVD-2020-46227 // JVNDB: JVNDB-2020-008695

EXTERNAL IDS

db:NVDid:CVE-2020-15896

Trust: 3.0

db:DLINKid:SAP10169

Trust: 1.6

db:JVNDBid:JVNDB-2020-008695

Trust: 0.8

db:CNVDid:CNVD-2020-46227

Trust: 0.6

db:CNNVDid:CNNVD-202007-1379

Trust: 0.6

sources: CNVD: CNVD-2020-46227 // JVNDB: JVNDB-2020-008695 // CNNVD: CNNVD-202007-1379 // NVD: CVE-2020-15896

REFERENCES

url:https://nvd.nist.gov/vuln/detail/cve-2020-15896

Trust: 2.0

url:https://research.loginsoft.com/bugs/authentication-bypass-in-d-link-firmware-dap-1522/

Trust: 1.6

url:https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=sap10169

Trust: 1.6

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2020-15896

Trust: 0.8

sources: CNVD: CNVD-2020-46227 // JVNDB: JVNDB-2020-008695 // CNNVD: CNNVD-202007-1379 // NVD: CVE-2020-15896

SOURCES

db:CNVDid:CNVD-2020-46227
db:JVNDBid:JVNDB-2020-008695
db:CNNVDid:CNNVD-202007-1379
db:NVDid:CVE-2020-15896

LAST UPDATE DATE

2024-11-23T21:51:25.926000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2020-46227date:2020-08-15T00:00:00
db:JVNDBid:JVNDB-2020-008695date:2020-09-18T00:00:00
db:CNNVDid:CNNVD-202007-1379date:2020-07-28T00:00:00
db:NVDid:CVE-2020-15896date:2024-11-21T05:06:24.080

SOURCES RELEASE DATE

db:CNVDid:CNVD-2020-46227date:2020-08-15T00:00:00
db:JVNDBid:JVNDB-2020-008695date:2020-09-18T00:00:00
db:CNNVDid:CNNVD-202007-1379date:2020-07-22T00:00:00
db:NVDid:CVE-2020-15896date:2020-07-22T19:15:12.897