Hard-coded Credentials Authentication Bypass Vulnerability in D-Link D-View
CVE-2023-44411

9.8CRITICAL

Key Information:

Vendor
D-link
Status
Vendor
CVE Published:
3 May 2024

Summary

This vulnerability pertains to the D-Link D-View software, where the InstallApplication class contains hard-coded credentials that allow remote attackers to bypass the authentication mechanism. This flaw exposes the system to unauthorized access, as exploiting this vulnerability does not require authentication, permitting attackers to connect to the system's remotely reachable database. This vulnerability highlights significant security concerns regarding credential management and the importance of regular software security audits.

Affected Version(s)

D-View DLink D-View8 1.0.2.13

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.