Overview
The D-Link DIR-130 and DIR-330 are vulnerable to authentication bypass of the remote login page, and do not sufficiently protect administrator credentials.
Description
The D-Link DIR-130, firmware version 1.23, and DIR-330, firmware version 1.12, are vulnerable to the following: CWE-294: Authentication Bypass by Capture-replay - CVE-2017-3191 |
Impact
A remote attacker may be able to obtain administrator credentials and access administrator functionality of the device. |
Solution
The CERT/CC is currently unaware of a practical solution to this problem. |
Restrict Access |
Vendor Information (Learn More)
Vendor | Status | Date Notified | Date Updated |
---|---|---|---|
D-Link Systems, Inc. | Affected | 25 Jan 2017 | 07 Mar 2017 |
'취약점 정보2' 카테고리의 다른 글
Microsoft SMBv1 Vulnerability (0) | 2017.03.17 |
---|---|
Adobe Flash Player 신규 취약점 보안 업데이트 권고 (0) | 2017.03.17 |
Drupal Core - Multiple Vulnerabilities - SA-CORE-2017-001 (0) | 2017.03.16 |
Apache Tomcat 9.x vulnerabilities (업데이트 권고) (0) | 2017.03.15 |
MS 3월 보안 위협에 따른 정기 보안 업데이트 권고 (0) | 2017.03.15 |