First published: Wed Dec 03 2014(Updated: )
D-link IP camera DCS-2103 with firmware 1.0.0 allows remote attackers to obtain the installation path via the file parameter to cgi-bin/sddownload.cgi, as demonstrated by a / (forward slash) character.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
D-Link DCS-2103 HD Cube Network Camera Firmware | =1.0.0 | |
D-Link DCS-2103 HD Cube Network Camera Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-9238 is classified as a medium severity vulnerability due to its potential for unauthorized access.
To fix CVE-2014-9238, update the firmware of the D-link DCS-2103 camera to a version that addresses this vulnerability.
CVE-2014-9238 is a directory traversal vulnerability that allows attackers to access sensitive file paths.
CVE-2014-9238 specifically affects the D-link DCS-2103 HD Cube Network Camera running firmware version 1.0.0.
Yes, CVE-2014-9238 can be exploited remotely, allowing attackers to obtain sensitive information.