CVE-2024-10916
Last modified
CVE-2024-10916 is a medium-severity vulnerability rated 6.9/10 on the CVSS scale. A vulnerability classified as problematic has been found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. This affects an unknown part of the file /xml/info.xml of the component HTTP GET Request Handler. EPSS estimates a 1.46% chance of exploitation in the next 30 days.
Description
A vulnerability classified as problematic has been found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. This affects an unknown part of the file /xml/info.xml of the component HTTP GET Request Handler. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dlink | Dns-320 Firmware | All versions |
| Dlink | Dns-320lw Firmware | All versions |
| Dlink | Dns-325 Firmware | All versions |
| Dlink | Dns-340l Firmware | All versions |
References
- https://vuldb.com/?ctiid.283311Third Party Advisory
- https://vuldb.com/?id.283311Third Party Advisory
- https://vuldb.com/?submit.432849Third Party Advisory
- https://www.dlink.com/Product
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-10916?
How severe is CVE-2024-10916?
How do I fix CVE-2024-10916?
Are you affected by CVE-2024-10916?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
