ID

VAR-201901-0599


CVE

CVE-2018-15515


TITLE

D-Link Central WiFiManager CWM-100 Vulnerabilities related to authorization, authority, and access control in devices

Trust: 0.8

sources: JVNDB: JVNDB-2018-014597

DESCRIPTION

The CaptivelPortal service on D-Link Central WiFiManager CWM-100 1.03 r0098 devices will load a Trojan horse "quserex.dll" from the CaptivelPortal.exe subdirectory under the D-Link directory, which allows unprivileged local users to gain SYSTEM privileges. D-Link Central WiFiManager CWM-100 Devices have vulnerabilities related to authorization, permissions, and access control.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. D-LINKCentralWifiManagerCWM-100 is D-LINK centralized wireless management software. The D-LinkCentral WiFi Manager CWM-1001.03r0098 device will load the Trojan horse \"quserex.dll\" and will create a new thread that runs the integrity of the SYSTEM

Trust: 2.16

sources: NVD: CVE-2018-15515 // JVNDB: JVNDB-2018-014597 // CNVD: CNVD-2018-22944

IOT TAXONOMY

category:['ICS', 'Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2018-22944

AFFECTED PRODUCTS

vendor:dlinkmodel:central wifimanagerscope:eqversion:1.03_r0098

Trust: 1.0

vendor:d linkmodel:central wifi managerscope:eqversion:cwm-100 1.03 r0098

Trust: 0.8

vendor:d linkmodel:central wifimanager (cwm r0098scope:eqversion:100)1.03

Trust: 0.6

sources: CNVD: CNVD-2018-22944 // JVNDB: JVNDB-2018-014597 // NVD: CVE-2018-15515

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-15515
value: HIGH

Trust: 1.0

NVD: CVE-2018-15515
value: HIGH

Trust: 0.8

CNVD: CNVD-2018-22944
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201811-282
value: HIGH

Trust: 0.6

nvd@nist.gov: CVE-2018-15515
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2018-22944
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2018-15515
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2018-22944 // JVNDB: JVNDB-2018-014597 // CNNVD: CNNVD-201811-282 // NVD: CVE-2018-15515

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:CWE-264

Trust: 0.8

sources: JVNDB: JVNDB-2018-014597 // NVD: CVE-2018-15515

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-201811-282

TYPE

permissions and access control issues

Trust: 0.6

sources: CNNVD: CNNVD-201811-282

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-014597

PATCH

title:Central WiFiManager Software Controllerurl:http://us.dlink.com/products/business-solutions/central-wifimanager-software-controller/

Trust: 0.8

sources: JVNDB: JVNDB-2018-014597

EXTERNAL IDS

db:NVDid:CVE-2018-15515

Trust: 3.0

db:PACKETSTORMid:150244

Trust: 2.4

db:JVNDBid:JVNDB-2018-014597

Trust: 0.8

db:CNVDid:CNVD-2018-22944

Trust: 0.6

db:CNNVDid:CNNVD-201811-282

Trust: 0.6

sources: CNVD: CNVD-2018-22944 // JVNDB: JVNDB-2018-014597 // CNNVD: CNNVD-201811-282 // NVD: CVE-2018-15515

REFERENCES

url:http://packetstormsecurity.com/files/150244/d-link-central-wifimanager-cwm-100-1.03-r0098-dll-hijacking.html

Trust: 2.4

url:http://seclists.org/fulldisclosure/2018/nov/29

Trust: 2.2

url:https://nvd.nist.gov/vuln/detail/cve-2018-15515

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-15515

Trust: 0.8

sources: CNVD: CNVD-2018-22944 // JVNDB: JVNDB-2018-014597 // CNNVD: CNNVD-201811-282 // NVD: CVE-2018-15515

SOURCES

db:CNVDid:CNVD-2018-22944
db:JVNDBid:JVNDB-2018-014597
db:CNNVDid:CNNVD-201811-282
db:NVDid:CVE-2018-15515

LAST UPDATE DATE

2024-11-23T22:58:47.281000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2018-22944date:2018-11-12T00:00:00
db:JVNDBid:JVNDB-2018-014597date:2019-03-29T00:00:00
db:CNNVDid:CNNVD-201811-282date:2019-10-23T00:00:00
db:NVDid:CVE-2018-15515date:2024-11-21T03:50:59.263

SOURCES RELEASE DATE

db:CNVDid:CNVD-2018-22944date:2018-11-12T00:00:00
db:JVNDBid:JVNDB-2018-014597date:2019-03-29T00:00:00
db:CNNVDid:CNNVD-201811-282date:2018-11-12T00:00:00
db:NVDid:CVE-2018-15515date:2019-01-31T19:29:00.233