PT-2023-5887 · D Link · D-Link D-View

·

CVE-2023-44413

·

Published

2023-10-04

·

Updated

2024-05-04

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions D-Link D-View (affected versions not specified)
Description This issue allows remote attackers to create a denial-of-service condition on affected installations of D-Link D-View. The specific flaw exists within the shutdown coreserver action, resulting from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider disabling the shutdown coreserver action until a patch is available. Restrict access to the shutdown coreserver functionality to minimize the risk of exploitation.

Missing Authentication

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-06580
CVE-2023-44413
ZDI-23-1511

Affected Products

D-Link D-View