CVE-2021-41504: High severity Dlink Dcs-932l Firmware vulnerability
UNSUPPORTED WHEN ASSIGNED An Elevated Privileges issue exists in D-Link DCS-5000L v1.05 and DCS-932L v2.17 and older. The use of the digest-authentication for the devices command interface may allow further attack vectors that may compromise the cameras configuration and allow malicious users on the LAN to access the device. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-41504.
What is the affected software?
The affected software includes D-Link DCS-5000L v1.05 and DCS-932L v2.17 and older.
What is the severity of CVE-2021-41504?
The severity of CVE-2021-41504 is high with a severity value of 8.
How does the vulnerability affect the cameras?
The vulnerability allows malicious users to compromise the cameras' configuration and potentially gain elevated privileges.
How can I find more information about this vulnerability?
You can find more information about this vulnerability in the following references: [Support Announcement](https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10247) and [Security Bulletin](https://www.dlink.com/en/security-bulletin/).