Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-41503


DCS-5000L v1.05 and DCS-932L v2.17 and older are affecged by Incorrect Acess Control. The use of the basic authentication for the devices command interface allows attack vectors that may compromise the cameras configuration and allow malicious users on the LAN to access the device. NOTE: This vulnerability only affects products that are no longer supported by the maintainer


Published

2021-09-24T20:15:07.373

Last Modified

2024-11-21T06:26:20.110

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.0 (HIGH)

CVSSv2 Vector

AV:A/AC:L/Au:S/C:P/I:P/A:P

  • Access Vector: ADJACENT_NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

5.1

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-287
  • Type: Secondary
    CWE-287

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System dlink dcs-932l_firmware ≤ 2.17 Yes
Hardware dlink dcs-932l - No
Operating System d-link dcs-5000l_firmware 1.05 Yes
Hardware dlink dcs-5000l - No

References