CVE-2023-51629: D-Link DCS-8300LHV2 ONVIF Hardcoded PIN Authentication Bypass Vulnerability
D-Link DCS-8300LHV2 ONVIF Hardcoded PIN Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DCS-8300LHV2 IP cameras. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the configuration of the ONVIF API. The issue results from the use of a hardcoded PIN. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-21492.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-51629?
CVE-2023-51629 is classified as a high severity vulnerability due to the potential for authentication bypass.
How do I fix CVE-2023-51629?
To fix CVE-2023-51629, update the DCS-8300LHV2 firmware to the latest version provided by D-Link.
Who is affected by CVE-2023-51629?
CVE-2023-51629 affects installations of D-Link DCS-8300LHV2 IP cameras running firmware versions up to 1.07.02.
What can attackers do with CVE-2023-51629?
Attackers can exploit CVE-2023-51629 to bypass authentication and gain unauthorized access to the camera's video feed.
Is authentication required to exploit CVE-2023-51629?
No, authentication is not required to exploit CVE-2023-51629, making it particularly dangerous.