CVE-2024-3274

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in D-Link DNS-320L, DNS-320LW and DNS-327L up to 20240403 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/info.cgi of the component HTTP GET Request Handler. The manipulation leads to information disclosure. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-259285 was assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.
Configurations

No configuration.

History

21 Nov 2024, 09:29

Type Values Removed Values Added
References () https://github.com/netsecfish/info_cgi - () https://github.com/netsecfish/info_cgi -
References () https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10383 - () https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10383 -
References () https://vuldb.com/?ctiid.259285 - () https://vuldb.com/?ctiid.259285 -
References () https://vuldb.com/?id.259285 - () https://vuldb.com/?id.259285 -
References () https://vuldb.com/?submit.304706 - () https://vuldb.com/?submit.304706 -

05 Apr 2024, 05:15

Type Values Removed Values Added
References
  • () https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10383 -
Summary
  • (es) ** NO COMPATIBLE CUANDO SE ASIGNÓ ** Se ha encontrado una vulnerabilidad en D-Link DNS-320L, DNS-320LW y DNS-327L hasta 20240403 y se ha clasificado como problemática. Una función desconocida del archivo /cgi-bin/info.cgi del componente HTTP GET Request Handler es afectada por esta vulnerabilidad. La manipulación conduce a la divulgación de información. El ataque se puede lanzar de forma remota. El exploit ha sido divulgado al público y puede utilizarse. A esta vulnerabilidad se le asignó el identificador VDB-259285. NOTA: Esta vulnerabilidad solo afecta a productos que ya no son compatibles con el fabricante. NOTA: Se contactó primeramente con el proveedor y se confirmó de inmediato que el producto ha llegado al final de su vida útil. Debería retirarse y reemplazarse.

04 Apr 2024, 04:15

Type Values Removed Values Added
Summary (en) A vulnerability has been found in D-Link DNS-320L, DNS-320LW and DNS-327L up to 20240403 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/info.cgi of the component HTTP GET Request Handler. The manipulation leads to information disclosure. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-259285 was assigned to this vulnerability. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced. (en) ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in D-Link DNS-320L, DNS-320LW and DNS-327L up to 20240403 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/info.cgi of the component HTTP GET Request Handler. The manipulation leads to information disclosure. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-259285 was assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.

04 Apr 2024, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-04 02:15

Updated : 2024-11-21 09:29


NVD link : CVE-2024-3274

Mitre link : CVE-2024-3274

CVE.ORG link : CVE-2024-3274


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor