« Volver al listado

CVE-2021-39613

Estado: ModificadaCrítica (9.8)—

** NO COMPATIBLE CUANDO SE ASIGNÓ ** D-Link DVG-3104MS versiones 1.0.2.0.3, 1.0.2.0.4 y 1.0.2.0.4E, contiene credenciales embebidas para cuentas de usuario no documentadas en el archivo "/etc/passwd". Como se han usado contraseñas débiles, unas contraseñas en texto plano pueden ser recuperadas de los valores hash. NOTA: Esta vulnerabilidad sólo afecta a los productos que ya no son compatibles por el mantenedor.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-39613",
  "cveTags": [
    {
      "tags": [
        "unsupported-when-assigned"
      ],
      "sourceIdentifier": "cve@mitre.org"
    }
  ],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2021-39613",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-07-30T16:04:52.795103Z"
        }
      }
    ],
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:o:dlink:dvg-3104ms_firmware:1.0.2.0.3:*:*:*:*:*:*:*"
          ],
          "vendor": "dlink",
          "product": "dvg-3104ms_firmware",
          "versions": [
            {
              "status": "affected",
              "version": "1.0.2.0.3"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:o:dlink:dvg-3104ms_firmware:1.0.2.0.4:*:*:*:*:*:*:*"
          ],
          "vendor": "dlink",
          "product": "dvg-3104ms_firmware",
          "versions": [
            {
              "status": "affected",
              "version": "1.0.2.0.4"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:o:dlink:dvg-3104ms_firmware:1.0.2.0.4e:*:*:*:*:*:*:*"
          ],
          "vendor": "dlink",
          "product": "dvg-3104ms_firmware",
          "versions": [
            {
              "status": "affected",
              "version": "1.0.2.0.4e"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2021-08-23T22:15:28.657",
  "references": [
    {
      "url": "https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10237",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.dlink.com/en/security-bulletin/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.nussko.com/advisories/advisory-2021-08-01.txt",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10237",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.dlink.com/en/security-bulletin/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.nussko.com/advisories/advisory-2021-08-01.txt",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-798"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-798"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "D-Link DVG-3104MS version 1.0.2.0.3, 1.0.2.0.4, and 1.0.2.0.4E contains hard-coded credentials for undocumented user accounts in the '/etc/passwd' file. As weak passwords have been used, the plaintext passwords can be recovered from the hash values. NOTE: This vulnerability only affects products that are no longer supported by the maintainer"
    },
    {
      "lang": "es",
      "value": "** NO COMPATIBLE CUANDO SE ASIGNÓ ** D-Link DVG-3104MS versiones 1.0.2.0.3, 1.0.2.0.4 y 1.0.2.0.4E, contiene credenciales embebidas para cuentas de usuario no documentadas en el archivo \"/etc/passwd\". Como se han usado contraseñas débiles, unas contraseñas en texto plano pueden ser recuperadas de los valores hash. NOTA: Esta vulnerabilidad sólo afecta a los productos que ya no son compatibles por el mantenedor."
    }
  ],
  "lastModified": "2026-06-17T04:03:52.907",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:dlink:dvg-3104ms_firmware:1.0.2.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C43934CD-7E3D-4F36-892F-B28B54931F24"
            },
            {
              "criteria": "cpe:2.3:o:dlink:dvg-3104ms_firmware:1.0.2.0.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0CC9C9A7-0987-4C99-BD7C-0F828D93F10F"
            },
            {
              "criteria": "cpe:2.3:o:dlink:dvg-3104ms_firmware:1.0.2.0.4e:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CE8EDE54-789A-4BC8-A834-A6A812E55A9B"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:dlink:dvg-3104ms:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "C53955CD-F4C7-420F-B456-817F4FBBBEBD"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}