CVE-2021-41503

Scores

EPSS

0.000none0.0%
0%20%40%60%80%100%

Percentile: 0.0%

CVSS

8.0high3.x
0246810

CVSS Score: 8.0/10

All CVSS Scores

CVSS 3.x
8.0

Vector: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS 2.0
5.2

Vector: AV:A/AC:L/Au:S/C:P/I:P/A:P

Description

DCS-5000L v1.05 and DCS-932L v2.17 and older are affecged by Incorrect Acess Control. The use of the basic authentication for the devices command interface allows attack vectors that may compromise the cameras configuration and allow malicious users on the LAN to access the device. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

CWEs

CWE-287

Vulnerable Software (2)

Type: Configuration

Vendor: d-link

Product: dcs-5000l_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:d-link:dcs-5000l_firmware:1.05:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator":...

Source: nvd

Type: Configuration

Vendor: dlink

Product: dcs-932l_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:dlink:dcs-932l_firmware:*:*:*:*:*:*:*:*",          "versionEndIncluding": "2.17",          "vulnerable": true...

Source: nvd