ID

VAR-202212-2045


CVE

CVE-2022-38873


TITLE

plural  D-Link  Vulnerabilities in devices

Trust: 0.8

sources: JVNDB: JVNDB-2022-003449

DESCRIPTION

D-Link devices DAP-2310 v2.10rc036 and earlier, DAP-2330 v1.06rc020 and earlier, DAP-2360 v2.10rc050 and earlier, DAP-2553 v3.10rc031 and earlier, DAP-2660 v1.15rc093 and earlier, DAP-2690 v3.20rc106 and earlier, DAP-2695 v1.20rc119_beta31 and earlier, DAP-3320 v1.05rc027 beta and earlier, DAP-3662 v1.05rc047 and earlier allows attackers to cause a Denial of Service (DoS) via uploading a crafted firmware after modifying the firmware header. plural D-Link There is an unspecified vulnerability in the device.Service operation interruption (DoS) It may be in a state

Trust: 1.62

sources: NVD: CVE-2022-38873 // JVNDB: JVNDB-2022-003449

AFFECTED PRODUCTS

vendor:dlinkmodel:dap-2553scope:lteversion:3.10rc031

Trust: 1.0

vendor:dlinkmodel:dap-2690scope:lteversion:3.20rc106

Trust: 1.0

vendor:dlinkmodel:dap-2660scope:lteversion:1.15rc093

Trust: 1.0

vendor:dlinkmodel:dap-2330scope:lteversion:1.06rc020

Trust: 1.0

vendor:dlinkmodel:dap-2695scope:ltversion:1.20rc119

Trust: 1.0

vendor:dlinkmodel:dap-2695scope:eqversion:1.20rc119

Trust: 1.0

vendor:dlinkmodel:dap-3320scope:ltversion:1.05rc027

Trust: 1.0

vendor:dlinkmodel:dap-3320scope:eqversion:1.05rc027

Trust: 1.0

vendor:dlinkmodel:dap-2310scope:lteversion:2.10rc036

Trust: 1.0

vendor:dlinkmodel:dap-2360scope:lteversion:2.10rc050

Trust: 1.0

vendor:dlinkmodel:dap-3662scope:lteversion:1.05rc047

Trust: 1.0

vendor:d linkmodel:dap-3320scope: - version: -

Trust: 0.8

vendor:d linkmodel:dap-2310scope: - version: -

Trust: 0.8

vendor:d linkmodel:dap-2360scope: - version: -

Trust: 0.8

vendor:d linkmodel:dap-2330scope: - version: -

Trust: 0.8

vendor:d linkmodel:dap-3662scope: - version: -

Trust: 0.8

vendor:d linkmodel:dap-2695scope: - version: -

Trust: 0.8

vendor:d linkmodel:dap-2660scope: - version: -

Trust: 0.8

vendor:d linkmodel:dap-2690scope: - version: -

Trust: 0.8

vendor:d linkmodel:dap-2553scope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2022-003449 // NVD: CVE-2022-38873

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2022-38873
value: HIGH

Trust: 1.0

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2022-38873
value: HIGH

Trust: 1.0

NVD: CVE-2022-38873
value: HIGH

Trust: 0.8

CNNVD: CNNVD-202212-3635
value: HIGH

Trust: 0.6

nvd@nist.gov: CVE-2022-38873
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.1

Trust: 2.0

NVD: CVE-2022-38873
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2022-003449 // CNNVD: CNNVD-202212-3635 // NVD: CVE-2022-38873 // NVD: CVE-2022-38873

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:CWE-345

Trust: 1.0

problemtype:Lack of information (CWE-noinfo) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2022-003449 // NVD: CVE-2022-38873

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202212-3635

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202212-3635

PATCH

title:Security Bulletinurl:https://www.dlink.com/en/security-bulletin

Trust: 0.8

sources: JVNDB: JVNDB-2022-003449

EXTERNAL IDS

db:NVDid:CVE-2022-38873

Trust: 3.2

db:JVNDBid:JVNDB-2022-003449

Trust: 0.8

db:CNNVDid:CNNVD-202212-3635

Trust: 0.6

sources: JVNDB: JVNDB-2022-003449 // CNNVD: CNNVD-202212-3635 // NVD: CVE-2022-38873

REFERENCES

url:https://www.dlink.com/en/security-bulletin/

Trust: 1.6

url:https://github.com/yuhao-w/bug--d-link--firmware-update-vulnerabilities/blob/main/readme.md

Trust: 1.6

url:https://nvd.nist.gov/vuln/detail/cve-2022-38873

Trust: 0.8

url:https://cxsecurity.com/cveshow/cve-2022-38873/

Trust: 0.6

sources: JVNDB: JVNDB-2022-003449 // CNNVD: CNNVD-202212-3635 // NVD: CVE-2022-38873

SOURCES

db:JVNDBid:JVNDB-2022-003449
db:CNNVDid:CNNVD-202212-3635
db:NVDid:CVE-2022-38873

LAST UPDATE DATE

2025-04-18T04:12:16.767000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2022-003449date:2023-02-17T08:59:00
db:CNNVDid:CNNVD-202212-3635date:2022-12-30T00:00:00
db:NVDid:CVE-2022-38873date:2025-04-17T14:15:20.023

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2022-003449date:2023-02-17T00:00:00
db:CNNVDid:CNNVD-202212-3635date:2022-12-20T00:00:00
db:NVDid:CVE-2022-38873date:2022-12-20T20:15:09.730