ID

VAR-202309-0935


CVE

CVE-2023-5151


TITLE

D-Link Systems, Inc.  of  dar-8000  in the firmware  SQL  Injection vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2023-012961

DESCRIPTION

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical was found in D-Link DAR-8000 up to 20151231. Affected by this vulnerability is an unknown functionality of the file /autheditpwd.php. The manipulation of the argument hid_id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-240247. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced. D-Link Systems, Inc. of dar-8000 The firmware has SQL There is an injection vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state

Trust: 1.62

sources: NVD: CVE-2023-5151 // JVNDB: JVNDB-2023-012961

AFFECTED PRODUCTS

vendor:dlinkmodel:dar-8000scope:lteversion:2015-12-31

Trust: 1.0

vendor:d linkmodel:dar-8000scope:eqversion: -

Trust: 0.8

vendor:d linkmodel:dar-8000scope: - version: -

Trust: 0.8

vendor:d linkmodel:dar-8000scope:lteversion:dar-8000 firmware 2015-12-31 and earlier

Trust: 0.8

sources: JVNDB: JVNDB-2023-012961 // NVD: CVE-2023-5151

CVSS

SEVERITY

CVSSV2

CVSSV3

cna@vuldb.com: CVE-2023-5151
value: MEDIUM

Trust: 1.0

nvd@nist.gov: CVE-2023-5151
value: HIGH

Trust: 1.0

NVD: CVE-2023-5151
value: HIGH

Trust: 0.8

cna@vuldb.com: CVE-2023-5151
severity: MEDIUM
baseScore: 6.5
vectorString: AV:N/AC:L/AU:S/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

cna@vuldb.com: CVE-2023-5151
baseSeverity: MEDIUM
baseScore: 6.3
vectorString: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: LOW
exploitabilityScore: 2.8
impactScore: 3.4
version: 3.1

Trust: 1.0

nvd@nist.gov: CVE-2023-5151
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 5.9
version: 3.1

Trust: 1.0

NVD: CVE-2023-5151
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2023-012961 // NVD: CVE-2023-5151 // NVD: CVE-2023-5151

PROBLEMTYPE DATA

problemtype:CWE-89

Trust: 1.0

problemtype:SQL injection (CWE-89) [ others ]

Trust: 0.8

sources: JVNDB: JVNDB-2023-012961 // NVD: CVE-2023-5151

EXTERNAL IDS

db:NVDid:CVE-2023-5151

Trust: 2.6

db:DLINKid:SAP10354

Trust: 1.8

db:VULDBid:240247

Trust: 1.8

db:JVNDBid:JVNDB-2023-012961

Trust: 0.8

sources: JVNDB: JVNDB-2023-012961 // NVD: CVE-2023-5151

REFERENCES

url:https://github.com/llixixi/cve/blob/main/d-link-dar-8000-10_sql_%20autheditpwd.md

Trust: 1.8

url:https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=sap10354

Trust: 1.8

url:https://vuldb.com/?ctiid.240247

Trust: 1.8

url:https://vuldb.com/?id.240247

Trust: 1.8

url:https://nvd.nist.gov/vuln/detail/cve-2023-5151

Trust: 0.8

sources: JVNDB: JVNDB-2023-012961 // NVD: CVE-2023-5151

SOURCES

db:JVNDBid:JVNDB-2023-012961
db:NVDid:CVE-2023-5151

LAST UPDATE DATE

2024-08-14T13:19:16.658000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2023-012961date:2023-12-19T07:57:00
db:NVDid:CVE-2023-5151date:2024-08-02T08:15:32.620

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2023-012961date:2023-12-19T00:00:00
db:NVDid:CVE-2023-5151date:2023-09-25T02:15:10.657