First published: Sun Dec 29 2019(Updated: )
On Netis DL4323 devices, any user role can view sensitive information, such as a user password or the FTP password, via the form2saveConf.cgi page.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netis-systems Dl4343 Firmware | ||
Netis-systems Dl4343 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-20074 is a vulnerability found in Netis DL4323 devices that allows any user role to view sensitive information.
Through the CVE-2019-20074 vulnerability, any user role can view sensitive information such as user passwords and FTP passwords.
To exploit CVE-2019-20074, an attacker would need to access the form2saveConf.cgi page on Netis DL4323 devices and select the user role to view sensitive information.
At the moment, there is no known fix for CVE-2019-20074. It is recommended to avoid using Netis DL4323 devices or to apply any security patches or updates provided by the manufacturer.
CVE-2019-20074 has a severity rating of 8.8, which is considered high.