Hardcoded PIN Authentication Bypass Vulnerability Affects D-Link DCS-8300LHV2 IP Cameras
CVE-2023-51629
8.8HIGH
Summary
The D-Link DCS-8300LHV2 IP cameras are susceptible to an authentication bypass vulnerability due to the implementation of a hardcoded PIN within the ONVIF API configuration. This flaw enables network-adjacent attackers to circumvent authentication mechanisms, creating a significant security risk as exploitation does not require any prior authentication. Organizations utilizing these cameras should take immediate action to secure their installations and mitigate potential unauthorized access.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published