{"id": "CVE-2024-7922", "cveTags": [{"tags": ["unsupported-when-assigned"], "sourceIdentifier": "cna@vuldb.com"}], "metrics": {"cvssMetricV2": [{"type": "Secondary", "source": "cna@vuldb.com", "cvssData": {"version": "2.0", "baseScore": 6.5, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P", "authentication": "SINGLE", "integrityImpact": "PARTIAL", "accessComplexity": "LOW", "availabilityImpact": "PARTIAL", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 6.4, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 8.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV31": [{"type": "Secondary", "source": "cna@vuldb.com", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 6.3, "attackVector": "NETWORK", "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L", "integrityImpact": "LOW", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "LOW", "privilegesRequired": "LOW", "confidentialityImpact": "LOW"}, "impactScore": 3.4, "exploitabilityScore": 2.8}, {"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 9.8, "attackVector": "NETWORK", "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}, "impactScore": 5.9, "exploitabilityScore": 3.9}], "cvssMetricV40": [{"type": "Secondary", "source": "cna@vuldb.com", "cvssData": {"safety": "NOT_DEFINED", "version": "4.0", "recovery": "NOT_DEFINED", "baseScore": 5.3, "automatable": "NOT_DEFINED", "attackVector": "NETWORK", "baseSeverity": "MEDIUM", "valueDensity": "NOT_DEFINED", "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X", "exploitMaturity": "NOT_DEFINED", "providerUrgency": "NOT_DEFINED", "userInteraction": "NONE", "attackComplexity": "LOW", "attackRequirements": "NONE", "privilegesRequired": "LOW", "modifiedAttackVector": "NOT_DEFINED", "integrityRequirements": "NOT_DEFINED", "modifiedUserInteraction": "NOT_DEFINED", "availabilityRequirements": "NOT_DEFINED", "modifiedAttackComplexity": "NOT_DEFINED", "subsequentSystemIntegrity": "NONE", "vulnerableSystemIntegrity": "LOW", "modifiedAttackRequirements": "NOT_DEFINED", "modifiedPrivilegesRequired": "NOT_DEFINED", "confidentialityRequirements": "NOT_DEFINED", "vulnerabilityResponseEffort": "NOT_DEFINED", "subsequentSystemAvailability": "NONE", "vulnerableSystemAvailability": "LOW", "subsequentSystemConfidentiality": "NONE", "vulnerableSystemConfidentiality": "LOW", "modifiedSubsequentSystemIntegrity": "NOT_DEFINED", "modifiedVulnerableSystemIntegrity": "NOT_DEFINED", "modifiedSubsequentSystemAvailability": "NOT_DEFINED", "modifiedVulnerableSystemAvailability": "NOT_DEFINED", "modifiedSubsequentSystemConfidentiality": "NOT_DEFINED", "modifiedVulnerableSystemConfidentiality": "NOT_DEFINED"}}]}, "published": "2024-08-19T15:15:09.403", "references": [{"url": "https://github.com/BuaaIOTTeam/Iot_Dlink_NAS/blob/main/DNS_cgi_create_playlist.md", "tags": ["Exploit"], "source": "cna@vuldb.com"}, {"url": "https://github.com/BuaaIOTTeam/Iot_Dlink_NAS/blob/main/DNS_cgi_get_tracks_list.md", "tags": ["Exploit"], "source": "cna@vuldb.com"}, {"url": "https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10383", "tags": ["Vendor Advisory"], "source": "cna@vuldb.com"}, {"url": "https://vuldb.com/?ctiid.275108", "tags": ["Permissions Required", "VDB Entry"], "source": "cna@vuldb.com"}, {"url": "https://vuldb.com/?id.275108", "tags": ["Permissions Required", "VDB Entry"], "source": "cna@vuldb.com"}, {"url": "https://vuldb.com/?submit.391669", "tags": ["Third Party Advisory", "VDB Entry"], "source": "cna@vuldb.com"}], "vulnStatus": "Analyzed", "weaknesses": [{"type": "Secondary", "source": "cna@vuldb.com", "description": [{"lang": "en", "value": "CWE-77"}]}], "descriptions": [{"lang": "en", "value": "A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814 and classified as critical. Affected by this issue is the function cgi_audio_search/cgi_create_playlist/cgi_get_album_all_tracks/cgi_get_alltracks_editlist/cgi_get_artist_all_album/cgi_get_genre_all_tracks/cgi_get_tracks_list/cgi_set_airplay_content/cgi_write_playlist of the file /cgi-bin/myMusic.cgi. The manipulation leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the product is end-of-life. It should be retired and replaced."}, {"lang": "es", "value": "Se encontr\u00f3 una vulnerabilidad en D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS- 326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 y DNS-1550-04 hasta 20240814 y clasificados como cr\u00edtico. Afectado por este problema es la funci\u00f3n CGI_AUDIO_SEARCH/CGI_CREATE_PLAYLIST/CGI_GET_ALBUM_ALL_TRACKS/CGI_GET_ALLTRACKS_EDITLIST/CGI_GET_ARTIST_ALL_ALBUM/CGI_GET_GENRE_ALL_TRACKS/CGI_GET_TRACKS/CGGI ite_playList del archivo /cgi-bin/mymusic.cgi. La manipulaci\u00f3n conduce a la inyecci\u00f3n de comandos. El ataque puede lanzarse de forma remota. El exploit ha sido divulgado al p\u00fablico y puede utilizarse. NOTA: Esta vulnerabilidad solo afecta a productos que ya no son compatibles con el fabricante. NOTA: Se contact\u00f3 primeramente con el proveedor y se confirm\u00f3 que el producto ha llegado al final de su vida \u00fatil. Deber\u00eda retirarse y reemplazarse."}], "lastModified": "2024-08-20T16:20:25.403", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:dell:dns-120_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B21A28B5-28EC-4307-938D-DFBEDB554DE5"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:dell:dns-120:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "577E4A7A-E036-4154-824A-ABBDF7B51D80"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:dell:dnr-202l_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "39244DF3-C362-419D-A6FF-1B8D8B716F97"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:dell:dnr-202l:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "F99805E4-E7D7-40D4-9340-1CCE337456FE"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:dell:dns-315l_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B0B1A621-3FE4-4C9B-9082-2DA311BCA88B"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:dell:dns-315l:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "7305E3CF-55F2-4885-BB74-FC0607D1DEF8"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:dell:dns-320_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "180B532E-DC78-496E-B362-6E09A2C3B209"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:dell:dns-320:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "DE7B6061-1B5E-47C7-981E-103C8532A5F2"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:dell:dns-320l_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2FF8C361-252B-4D72-923A-3F1EE660904C"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:dell:dns-320l:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "691EDA1F-77F4-4448-A6FE-AC280D8A1C84"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:dell:dns-320lw_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "92854E27-F1C7-42A4-91B0-D12EE805A191"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:dell:dns-320lw:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "49987828-78FF-4571-8382-5CE15EDC8092"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:dell:dns-321_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "12F66A8B-4985-4F6F-BECB-74A7D53FE5EA"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:dell:dns-321:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "0F2B198D-7991-4B8C-981F-40DE5C948140"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:dell:dnr-322l_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "ED124802-3717-4D45-AE2B-ECE20876FB22"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:dell:dnr-322l:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "908FF5BC-9EA8-476E-BB3B-5B839C4855CC"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:dell:dns-323_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3EA2156D-ED3B-4E4E-9E22-A8AC6B12CAE8"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:dell:dns-323:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "DD4C6779-9E57-4B64-BE79-356046955B42"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:dell:dns-325_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "574481BB-B541-4B84-A935-64EB872100F9"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:dell:dns-325:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "77CFAE33-FB2C-4239-8674-F19A8628A3A0"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:dell:dns-326_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "151E7B4E-F2CD-4090-BA3F-721B85B7EA70"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:dell:dns-326:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "2E8D94FF-81FA-43BC-AA9A-6DDD578060C7"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:dell:dns-327l_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "37C7B7F4-E654-47A7-8541-B49CD2F76A80"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:dell:dns-327l:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "E2CDA9CA-7092-4090-AC15-7641A8E268F8"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:dell:dnr-326_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9D935868-7250-4E4A-AE30-FE383023DC03"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:dell:dnr-326:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "4DE48A4B-7F22-4EE3-9842-A9BDEBC11058"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:dell:dns-340l_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "85430BEE-D18E-4BC9-BE72-04440857E205"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:dell:dns-340l:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "B88232B8-047D-496A-B14E-138BEEB64984"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:dell:dns-343_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "88ABA04D-D603-4ACF-B165-F94A91920803"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:dell:dns-343:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "D1B2DBDA-C357-41B5-BDEF-9855A8042E2B"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:dell:dns-345_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B49595DE-4CE1-445B-B750-68615A80A8DF"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:dell:dns-345:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "F4AF004B-2BA8-4EE4-81AE-5A4F635059C8"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:dell:dns-726-4_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EA638D44-7851-4999-804F-EEFFA98D6E6A"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:dell:dns-726-4:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "423AD338-46E1-4B73-8974-C2DA4E47240C"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:dell:dns-1100-4_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0E919D37-0C27-45F9-922B-1E65983FDBA5"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:dell:dns-1100-4:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "4AABE548-E243-4237-9225-38A5FFCD829F"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:dell:dns-1200-05_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "65DB23C2-7FB0-48B8-BED6-0896B2B18D7E"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:dell:dns-1200-05:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "A62D373D-60A7-41A5-B66B-418B97A9BA00"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:dell:dns-1550-04_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A4EACE54-DE9E-4602-80C7-5121CFDAA616"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:dell:dns-1550-04:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "0561471D-6B18-43C9-B65B-32B6065275B6"}], "operator": "OR"}], "operator": "AND"}], "sourceIdentifier": "cna@vuldb.com"}