// For flags

CVE-2018-7698

 

Severity Score

8.1
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

An issue was discovered in D-Link mydlink+ 3.8.5 build 259 for DCS-933L 1.05.04 and DCS-934L 1.05.04 devices. The mydlink+ app sends the username and password for connected D-Link cameras (such as DCS-933L and DCS-934L) unencrypted from the app to the camera, allowing attackers to obtain these credentials and gain control of the camera including the ability to view the camera's stream and make changes without the user's knowledge.

Se ha descubierto un problema en D-Link mydlink+ 3.8.5 build 259 para dispositivos DCS-933L 1.05.04 y DCS-934L 1.05.04. La aplicación mydlink+ envía el nombre de usuario y la contraseña para las cámaras D-Link conectadas (como DCS-933L y DCS-934L) sin cifrar de la aplicación a la cámara. Esto permite que atacantes obtengan estas credenciales y obtengan el control de la cámara, incluyendo la capacidad de ver la transmisión de la cámara y realizar cambios sin que el usuario lo sepa.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2018-03-05 CVE Reserved
  • 2018-03-05 CVE Published
  • 2024-08-05 CVE Updated
  • 2024-11-15 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-522: Insufficiently Protected Credentials
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
D-link
Search vendor "D-link"
Mydlink\+
Search vendor "D-link" for product "Mydlink\+"
3.8.5
Search vendor "D-link" for product "Mydlink\+" and version "3.8.5"
-
Affected