CVE-2019-20074: High severity netis systems dl4343 firmware vulnerability
On Netis DL4323 devices, any user role can view sensitive information, such as a user password or the FTP password, via the form2saveConf.cgi page.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-20074?
CVE-2019-20074 is a vulnerability found in Netis DL4323 devices that allows any user role to view sensitive information.
What type of sensitive information can be viewed through CVE-2019-20074?
Through the CVE-2019-20074 vulnerability, any user role can view sensitive information such as user passwords and FTP passwords.
How can I exploit CVE-2019-20074?
To exploit CVE-2019-20074, an attacker would need to access the form2saveConf.cgi page on Netis DL4323 devices and select the user role to view sensitive information.
Is there a fix available for CVE-2019-20074?
At the moment, there is no known fix for CVE-2019-20074. It is recommended to avoid using Netis DL4323 devices or to apply any security patches or updates provided by the manufacturer.
What is the severity rating of CVE-2019-20074?
CVE-2019-20074 has a severity rating of 8.8, which is considered high.