CVE-2024-33345: Null Pointer Dereference
Published Apr 29, 2024
·Updated
D-Link DIR-823G A1V1.0.2B05 was found to contain a Null-pointer dereference in the main function of uploadfirmware.cgi, which allows remote attackers to cause a Denial of Service (DoS) via a crafted input.
Affected Software
3 affected components
D-Link DIR-823G
All of the following
Dlink Dir-823g Firmware=1.0.2b05
Dlink Dir-823g=a1
Event History
Apr 29, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-33345?
CVE-2024-33345 is classified as a medium severity vulnerability due to its potential to cause Denial of Service.
2
How do I fix CVE-2024-33345?
Fixing CVE-2024-33345 involves updating the firmware of the D-Link DIR-823G to the latest version provided by the manufacturer.
3
What type of attack does CVE-2024-33345 facilitate?
CVE-2024-33345 facilitates a Denial of Service (DoS) attack through a null-pointer dereference.
4
Who is affected by CVE-2024-33345?
CVE-2024-33345 affects users of the D-Link DIR-823G router running the vulnerable firmware version.
5
Can CVE-2024-33345 be exploited remotely?
Yes, CVE-2024-33345 can be exploited remotely by attackers sending crafted input to the affected device.