D-Link DIR-1950 up to v1.11B03 does not validate SSL certificates when requesting the latest firmware version and downloading URL. This can allow attackers to downgrade the firmware version or change the downloading URL via a man-in-the-middle attack.
References
Configurations
No configuration.
History
21 Nov 2024, 09:22
Type | Values Removed | Values Added |
---|---|---|
References | () https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10401 - |
01 Aug 2024, 13:53
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-599 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.8 |
Summary |
|
27 Jun 2024, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-06-27 21:15
Updated : 2024-11-21 09:22
NVD link : CVE-2024-36755
Mitre link : CVE-2024-36755
CVE.ORG link : CVE-2024-36755
JSON object : View
Products Affected
No product.
CWE
CWE-599
Missing Validation of OpenSSL Certificate