CVE-2017-14422
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices use the same hardcoded /etc/stunnel.key private key across different customers' installations, which allows remote attackers to defeat the HTTPS cryptographic protection mechanisms by leveraging knowledge of this key from another installation.
Los dispositivos D-Link DIR-850L REV. A (con firmware hasta la versión FW114WWb07_h2ab_beta1) y REV. B (con firmware hasta la versión FW208WWb02) emplean la misma clave embebida /etc/stunnel.key a lo largo de instalaciones de diferentes clientes, lo que permite que atacantes remotos superen los mecanismos de protección criptográfica HTTPS aprovechando el hecho de que conocen esta clave por otra instalación.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-09-13 CVE Reserved
- 2017-09-13 CVE Published
- 2023-11-09 EPSS Updated
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-798: Use of Hard-coded Credentials
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://pierrekim.github.io/blog/2017-09-08-dlink-850l-mydlink-cloud-0days-vulnerabilities.html | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Dlink Search vendor "Dlink" | Dir-850l Firmware Search vendor "Dlink" for product "Dir-850l Firmware" | < fw114wwb07_h2ab Search vendor "Dlink" for product "Dir-850l Firmware" and version " < fw114wwb07_h2ab" | - |
Affected
| in | Dlink Search vendor "Dlink" | Dir-850l Search vendor "Dlink" for product "Dir-850l" | - | - |
Safe
|
Dlink Search vendor "Dlink" | Dir-850l Firmware Search vendor "Dlink" for product "Dir-850l Firmware" | fw114wwb07_h2ab Search vendor "Dlink" for product "Dir-850l Firmware" and version "fw114wwb07_h2ab" | beta1 |
Affected
| in | Dlink Search vendor "Dlink" | Dir-850l Search vendor "Dlink" for product "Dir-850l" | - | - |
Safe
|
Dlink Search vendor "Dlink" | Dir-850l Firmware Search vendor "Dlink" for product "Dir-850l Firmware" | <= fw208wwb02 Search vendor "Dlink" for product "Dir-850l Firmware" and version " <= fw208wwb02" | - |
Affected
| in | Dlink Search vendor "Dlink" | Dir-850l Search vendor "Dlink" for product "Dir-850l" | - | - |
Safe
|