« Volver al listado

CVE-2017-3192

Estado: ModificadaCrítica (9.8)—

D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 do not sufficiently protect administrator credentials. The tools_admin.asp page discloses the administrator password in base64 encoding in the returned web page. A remote attacker with access to this page (potentially through a authentication bypass such as CVE-2017-3191) may obtain administrator credentials for the device.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-3192",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cret@cert.org",
      "affectedData": [
        {
          "vendor": "D-Link",
          "product": "DIR-130",
          "versions": [
            {
              "status": "affected",
              "version": "1.23"
            }
          ]
        },
        {
          "vendor": "D-Link",
          "product": "DIR-330",
          "versions": [
            {
              "status": "affected",
              "version": "1.12"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-12-16T02:29:10.323",
  "references": [
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/123292",
      "tags": [
        "Issue Tracking",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "https://www.kb.cert.org/vuls/id/553503",
      "tags": [
        "Issue Tracking",
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "https://www.scmagazine.com/d-link-dir-130-and-dir-330-routers-vulnerable/article/644553/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "https://www.wilderssecurity.com/threads/d-link-dir-130-and-dir-330-are-vulnerable-to-authentication-bypass-and-do-not-protect-credentials.392703/",
      "tags": [
        "Issue Tracking",
        "Third Party Advisory"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/123292",
      "tags": [
        "Issue Tracking",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.kb.cert.org/vuls/id/553503",
      "tags": [
        "Issue Tracking",
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.scmagazine.com/d-link-dir-130-and-dir-330-routers-vulnerable/article/644553/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.wilderssecurity.com/threads/d-link-dir-130-and-dir-330-are-vulnerable-to-authentication-bypass-and-do-not-protect-credentials.392703/",
      "tags": [
        "Issue Tracking",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cret@cert.org",
      "description": [
        {
          "lang": "en",
          "value": "CWE-522"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-522"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 do not sufficiently protect administrator credentials. The tools_admin.asp page discloses the administrator password in base64 encoding in the returned web page. A remote attacker with access to this page (potentially through a authentication bypass such as CVE-2017-3191) may obtain administrator credentials for the device."
    },
    {
      "lang": "es",
      "value": "La versión de firmware 1.23 de DIR-130 y la versión de firmware 1.12 de DIR-330 de D-Link no protegen suficientemente las credenciales de administrador. La página tools_admin.asp revela la contraseña del administrador en codificación base64 en la página web de retorno. Un atacante remoto con acceso a esta página (pudiendo ser mediante una omisión de autenticación como CVE-2017-3191) puede obtener credenciales de administrador para el dispositivo."
    }
  ],
  "lastModified": "2026-06-17T01:17:42.280",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:d-link:dir-130_firmware:1.23:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5800812B-C749-4D9C-8E2C-BF8EFE56FFF6"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:dlink:dir-130:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "EDAD83C8-CA60-4E7A-985A-89967A321D6E"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:d-link:dir-330_firmware:1.12:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "635BCAA5-F5F4-4387-A8C4-8C7605B8CF88"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:dlink:dir-330:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "C21B7018-6D23-4698-8B0F-7C34DCDCF0F2"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cret@cert.org"
}