CVE-2021-41503: High severity Dlink Dcs-932l Firmware vulnerability
UNSUPPORTED WHEN ASSIGNED DCS-5000L v1.05 and DCS-932L v2.17 and older are affecged by Incorrect Acess Control. The use of the basic authentication for the devices command interface allows attack vectors that may compromise the cameras configuration and allow malicious users on the LAN to access the device. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict network access to the camera device command interface (LAN) to trusted sources only to mitigate attacks leveraging basic authentication, since DCS-5000L v1.05 and DCS-932L v2.17 and older are affected.
Event History
Frequently Asked Questions
What is the severity of CVE-2021-41503?
The severity of CVE-2021-41503 is high.
Which devices are affected by CVE-2021-41503?
DCS-5000L v1.05 and DCS-932L v2.17 and older firmware versions are affected by CVE-2021-41503.
What is the vulnerability in CVE-2021-41503?
The vulnerability in CVE-2021-41503 is Incorrect Access Control.
How does the vulnerability in CVE-2021-41503 impact the cameras?
The vulnerability in CVE-2021-41503 may compromise the cameras' configuration and allow malicious users on the LAN to access them.
How can I fix CVE-2021-41503?
It is recommended to update the firmware of the DCS-5000L and DCS-932L cameras to a supported version to mitigate the CVE-2021-41503 vulnerability.