D-Link D-View Missing Authentication Denial-of-Service Vulnerability
CVE-2023-44413

5.9MEDIUM

Key Information:

Vendor
D-link
Status
Vendor
CVE Published:
3 May 2024

Summary

A vulnerability exists in D-Link D-View related to the shutdown_coreserver action, where a lack of proper authentication allows attackers to gain unauthorized access. This flaw can be exploited remotely, leading to a denial-of-service condition. By leveraging this vulnerability, an attacker can interfere with the normal operation of the D-View system without needing to authenticate, making it a significant security concern for organizations relying on this platform.

Affected Version(s)

D-View DLink D-View8 1.0.2.13

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.