Lucene search

K
cveMitreCVE-2019-7388
HistoryFeb 05, 2019 - 12:29 a.m.

CVE-2019-7388

2019-02-0500:29:00
CWE-200
mitre
web.nvd.nist.gov
19
cve-2019-7388
d-link dir-823g
firmware vulnerability
access control
information disclosure
wlan security

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.3

Confidence

High

EPSS

0.009

Percentile

83.1%

An issue was discovered in /bin/goahead on D-Link DIR-823G devices with firmware 1.02B03. There is incorrect access control allowing remote attackers to get sensitive information (such as MAC address) about all clients in the WLAN via the GetClientInfo HNAP API. Consequently, an attacker can achieve information disclosure without authentication.

Affected configurations

Nvd
Node
dlinkdir-823g_firmwareMatch1.02b03
AND
dlinkdir-823gMatch-
VendorProductVersionCPE
dlinkdir-823g_firmware1.02b03cpe:2.3:o:dlink:dir-823g_firmware:1.02b03:*:*:*:*:*:*:*
dlinkdir-823g-cpe:2.3:h:dlink:dir-823g:-:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.3

Confidence

High

EPSS

0.009

Percentile

83.1%

Related for CVE-2019-7388