CVE-2024-5296

D-Link D-View Use of Hard-coded Cryptographic Key Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of D-Link D-View. Authentication is not required to exploit this vulnerability. The specific flaw exists within the TokenUtils class. The issue results from a hard-coded cryptographic key. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-21991.
Configurations

No configuration.

History

21 Nov 2024, 09:47

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad de omisión de autenticación de clave criptográfica codificada mediante D-Link D-View. Esta vulnerabilidad permite a atacantes remotos eludir la autenticación en las instalaciones afectadas de D-Link D-View. No se requiere autenticación para aprovechar esta vulnerabilidad. La falla específica existe dentro de la clase TokenUtils. El problema se debe a una clave criptográfica codificada. Un atacante puede aprovechar esta vulnerabilidad para eludir la autenticación en el sistema. Era ZDI-CAN-21991.
References () https://www.zerodayinitiative.com/advisories/ZDI-24-447/ - () https://www.zerodayinitiative.com/advisories/ZDI-24-447/ -

23 May 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-23 22:15

Updated : 2024-11-21 09:47


NVD link : CVE-2024-5296

Mitre link : CVE-2024-5296

CVE.ORG link : CVE-2024-5296


JSON object : View

Products Affected

No product.

CWE
CWE-321

Use of Hard-coded Cryptographic Key