CVE-2012-4046: Infoleak
Published Dec 24, 2012
·Updated
The D-Link DCS-932L camera with firmware 1.02 allows remote attackers to discover the password via a UDP broadcast packet, as demonstrated by running the D-Link Setup Wizard and reading the paramR["P"] value.
Affected Software
2 affected components
Dlink Dcs-932l Firmware=1.02
Dlink Dcs-932l
Event History
Dec 24, 2012
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-4046?
CVE-2012-4046 has a moderate severity level as it allows remote attackers to discover passwords.
2
How do I fix CVE-2012-4046?
To fix CVE-2012-4046, update the D-Link DCS-932L firmware to a later version that addresses this vulnerability.
3
What systems are affected by CVE-2012-4046?
CVE-2012-4046 affects the D-Link DCS-932L camera specifically running firmware version 1.02.
4
What is the impact of CVE-2012-4046?
The impact of CVE-2012-4046 allows unauthorized users to retrieve the camera's password via a network broadcast.
5
Is CVE-2012-4046 exploited remotely?
Yes, CVE-2012-4046 can be exploited remotely by sending a UDP broadcast packet.