ZDI-CAN-19572: ZDI-23-1511: (0Day) D-Link D-View shutdown_coreserver Missing Authentication Denial-of-Service Vulnerability
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of D-Link D-View. Authentication is not required to exploit this vulnerability. The specific flaw exists within the shutdowncoreserver action. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.
Other sources
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of D-Link D-View. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.9. The following CVEs are assigned: CVE-2023-44413.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-19572?
ZDI-CAN-19572 has been classified as a denial-of-service vulnerability.
How do I fix ZDI-CAN-19572?
To fix ZDI-CAN-19572, update your D-Link D-View software to the latest version provided by the vendor.
Who is affected by ZDI-CAN-19572?
All installations of D-Link D-View are affected by ZDI-CAN-19572.
Is authentication required to exploit ZDI-CAN-19572?
No, authentication is not required to exploit ZDI-CAN-19572.
What type of attack does ZDI-CAN-19572 enable?
ZDI-CAN-19572 enables remote attackers to create a denial-of-service condition.