Lucene search

K
cveVulDBCVE-2024-1786
HistoryFeb 23, 2024 - 1:15 a.m.

CVE-2024-1786

2024-02-2301:15:53
CWE-120
VulDB
web.nvd.nist.gov
61
cve-2024-1786
d-link
dir-600m
c1
3.08
telnet service
buffer overflow
vulnerability
nvd

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.6

Confidence

High

EPSS

0

Percentile

15.5%

UNSUPPORTED WHEN ASSIGNED A vulnerability, which was classified as critical, has been found in D-Link DIR-600M C1 3.08. Affected by this issue is some unknown functionality of the component Telnet Service. The manipulation of the argument username leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-254576. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.

Affected configurations

Vulners
Vulnrichment
Node
d-linkdir-600m_c1_firmwareMatch3.08
VendorProductVersionCPE
d-linkdir-600m_c1_firmware3.08cpe:2.3:o:d-link:dir-600m_c1_firmware:3.08:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "D-Link",
    "product": "DIR-600M C1",
    "versions": [
      {
        "version": "3.08",
        "status": "affected"
      }
    ],
    "modules": [
      "Telnet Service"
    ]
  }
]

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.6

Confidence

High

EPSS

0

Percentile

15.5%

Related for CVE-2024-1786