Back to overview

CVE-2023-7163

CRITICAL
10.0
CVSS 3.1
Description
A security issue exists in D-Link D-View 8 v2.0.2.89 and prior that could allow an attacker to manipulate the probe inventory of the D-View service. This could result in the disclosure of information from other probes, denial of service conditions due to the probe inventory becoming full, or the execution of tasks on other probes.

Metadata

CVE ID
CVE-2023-7163
State
PUBLISHED
Assigner
tenable
Reserved
2023-12-28 15:18 UTC
Published
2023-12-28 15:37 UTC
Last updated
2024-08-02 08:50 UTC
Primary CWE
CWE-20
CWE-20 Improper Input Validation
Vendor / Product
D-Link / D-View 8
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products (1)
VendorProductPlatformVersions
D-Link D-View 8 0 ≤ 2.0.2.89
Weakness (CWE)
CWESourceDescription
CWE-20 cna CWE-20 Improper Input Validation
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview