[Japanese]
|
JVNDB-2021-001343
|
D-Link DAP-1880AC contains multiple vulnerabilities
|
DAP-1880AC provided by D-Link Japan K.K. contains multiple vulnerabilities listed below.
* Improper access control (CWE-284) - CVE-2021-20694
* Improper privilege management (CWE-269) - CVE-2021-20695
* OS command injection (CWE-78) - CVE-2021-20696
* Missing authentication for critical function (CWE-306) - CVE-2021-20697
Chuya Hayakawa of 00One, Inc. reported this vulnerability to JPCERT/CC.
JPCERT/CC coordinated with the developer.
|
CVSS V3 Severity: Base Metrics 5.0 (Medium) [IPA Score]
- Attack Vector: Network
- Attack Complexity: High
- Privileges Required: Low
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact: Low
- Integrity Impact: Low
- Availability Impact: Low
The above CVSS base scores have been assigned for CVE-2021-20694
|
CVSS V3 Severity:
Base Metrics:
8.8 (High) [IPA Score]
-
Attack Vector: Network
-
Attack Complexity: Low
-
Privileges Required: Low
-
User Interaction: None
-
Scope: Unchanged
-
Confidentiality Impact: High
-
Integrity Impact: High
-
Availability Impact: High
The above CVSS base scores have been assigned for CVE-2021-20695
|
CVSS V3 Severity:
Base Metrics:
6.3 (Medium) [IPA Score]
-
Attack Vector: Network
-
Attack Complexity: Low
-
Privileges Required: Low
-
User Interaction: None
-
Scope: Unchanged
-
Confidentiality Impact: Low
-
Integrity Impact: Low
-
Availability Impact: Low
The above CVSS base scores have been assigned for CVE-2021-20696
|
CVSS V3 Severity:
Base Metrics:
7.3 (High) [IPA Score]
-
Attack Vector: Network
-
Attack Complexity: Low
-
Privileges Required: None
-
User Interaction: None
-
Scope: Unchanged
-
Confidentiality Impact: Low
-
Integrity Impact: Low
-
Availability Impact: Low
The above CVSS base scores have been assigned for CVE-2021-20697
|
|
D-Link Systems, Inc.
- DAP-1880AC firmware firmware version 1.21 and prior
|
|
* An authenticated remote attacker can start telnet service. - CVE-2021-20694
* A low-privileged remote attacker can gain root privileges. - CVE-2021-20695
* If an authenticated remote attacker can send a specially crafted request to a specific CGI program, it may lead to an arbitrary OS command injection. - CVE-2021-20696
* A remote attacker can login to the product as a low-privileged user without the access privilege. - CVE-2021-20697
|
[Update firmware]
Update firmware to the latest version according to the information provided by the developer.
The developer has released the fixed version 1.23.
|
D-Link Systems, Inc.
|
- Improper Privilege Management(CWE-269) [IPA Evaluation]
- Improper Access Control(CWE-284) [IPA Evaluation]
- Missing Authentication for Critical Function(CWE-306) [IPA Evaluation]
- OS Command Injection(CWE-78) [IPA Evaluation]
|
- CVE-2021-20694
- CVE-2021-20695
- CVE-2021-20696
- CVE-2021-20697
|
- JVN : JVNVU#92898656
- National Vulnerability Database (NVD) : CVE-2021-20694
- National Vulnerability Database (NVD) : CVE-2021-20695
- National Vulnerability Database (NVD) : CVE-2021-20696
- National Vulnerability Database (NVD) : CVE-2021-20697
|
- [2021/04/12]
Web page was published
|