CVE-2019-19597
HIGH
8,8
Source: [email protected]
Attack Vector: adjacent_network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: high
HIGH
8,3
Source: [email protected]
Access Vector: adjacent_network
Access Complexity: low
Authentication: none
Confidentiality: complete
Integrity: complete
Availability: complete
Description
AI Translation Available
D-Link DAP-1860 devices before v1.04b03 Beta allow arbitrary remote code execution as root without authentication via shell metacharacters within an HNAP_AUTH HTTP header.
EPSS (Exploit Prediction Scoring System)
Trend Analysis
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score
0,0843
Percentile
0,9th
Updated
EPSS Score Trend (Last 91 Days)
863
Incorrect Authorization
IncompleteCommon Consequences
Security Scopes Affected:
Confidentiality
Integrity
Access Control
Availability
Potential Impacts:
Read Application Data
Read Files Or Directories
Modify Application Data
Modify Files Or Directories
Gain Privileges Or Assume Identity
Bypass Protection Mechanism
Execute Unauthorized Code Or Commands
Dos: Crash, Exit, Or Restart
Dos: Resource Consumption (Cpu)
Dos: Resource Consumption (Memory)
Dos: Resource Consumption (Other)
Applicable Platforms
Technologies:
Database Server, Not Technology-Specific, Web Server
Operating System
Dap-1860 Firmware by Dlink
CPE Identifier
View Detailed Analysis
cpe:2.3:o:dlink:dap-1860_firmware:1.01b06:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Dap-1860 Firmware by Dlink
CPE Identifier
View Detailed Analysis
cpe:2.3:o:dlink:dap-1860_firmware:1.04b01:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Dap-1860 Firmware by Dlink
CPE Identifier
View Detailed Analysis
cpe:2.3:o:dlink:dap-1860_firmware:1.02b01:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://chung96vn.wordpress.com/2019/11/15/d-link-dap-1860-vulnerabilities/
https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP…
https://chung96vn.wordpress.com/2019/11/15/d-link-dap-1860-vulnerabilities/
https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP…