First published: Wed Sep 20 2023(Updated: )
Use of a static key to protect a JWT token used in user authentication can allow an for an authentication bypass in D-Link D-View 8 v2.0.1.28
Credit: vulnreport@tenable.com vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dlink D-view 8 | =2.0.1.28 | |
=2.0.1.28 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-5074 is a vulnerability that allows an authentication bypass in D-Link D-View 8 v2.0.1.28 due to the use of a static key to protect a JWT token used in user authentication.
CVE-2023-5074 has a severity rating of 9.8 out of 10, indicating a critical vulnerability.
D-Link D-View 8 v2.0.1.28 is the affected software version.
CVE-2023-5074 is associated with CWE-798, which is the Weaknesses in OWASP Top Ten (2013).
You can find more information about CVE-2023-5074 at the following reference: [Tenable Security Advisory](https://www.tenable.com/security/research/tra-2023-32).