製品・ソフトウェアに関する情報
複数の D-Link DCS カメラにおけるクロスサイトリクエストフォージェリの脆弱性
Title 複数の D-Link DCS カメラにおけるクロスサイトリクエストフォージェリの脆弱性
Summary

複数の D-Link DCS カメラには、クロスサイトリクエストフォージェリの脆弱性が存在します。

Possible impacts 情報を取得される、情報を改ざんされる、およびサービス運用妨害 (DoS) 攻撃が行われる可能性があります。
Solution

ベンダ情報および参考情報を参照して適切な対策を実施してください。

Publication Date Feb. 22, 2017, midnight
Registration Date June 1, 2017, 6:42 p.m.
Last Update June 1, 2017, 6:42 p.m.
CVSS3.0 : 重要
Score 8.8
Vector CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS2.0 : 警告
Score 6.8
Vector AV:N/AC:M/Au:N/C:P/I:P/A:P
Affected System
D-Link Systems, Inc.
DCS-2132L ファームウェア 
DCS-2136L ファームウェア 
DCS-2210L ファームウェア 
DCS-2230L ファームウェア 
DCS-2310L ファームウェア 
DCS-2330L ファームウェア 
DCS-2332L ファームウェア 
DCS-2530L ファームウェア 
DCS-5000L ファームウェア 
DCS-5009L ファームウェア 
DCS-5010L ファームウェア 
DCS-5020L ファームウェア 
DCS-5025L ファームウェア 
DCS-5029L ファームウェア 
DCS-5030L ファームウェア 
DCS-5222L ファームウェア 
DCS-6010L ファームウェア 
DCS-6212L ファームウェア 
DCS-7000L ファームウェア 
DCS-7010L ファームウェア 
DCS-930L ファームウェア 
DCS-931L ファームウェア 
DCS-932L ファームウェア 
DCS-933L ファームウェア 
DCS-934L ファームウェア 
DCS-942L ファームウェア 
CVE (情報セキュリティ 共通脆弱性識別子)
CWE (共通脆弱性タイプ一覧)
ベンダー情報
その他
Change Log
No Changed Details Date of change
0 [2017年06月01日]
  掲載
Feb. 17, 2018, 10:37 a.m.

NVD Vulnerability Information
CVE-2017-7852
Summary

D-Link DCS cameras have a weak/insecure CrossDomain.XML file that allows sites hosting malicious Flash objects to access and/or change the device's settings via a CSRF attack. This is because of the 'allow-access-from domain' child element set to *, thus accepting requests from any domain. If a victim logged into the camera's web console visits a malicious site hosting a malicious Flash file from another Browser tab, the malicious Flash file then can send requests to the victim's DCS series Camera without knowing the credentials. An attacker can host a malicious Flash file that can retrieve Live Feeds or information from the victim's DCS series Camera, add new admin users, or make other changes to the device. Known affected devices are DCS-933L with firmware before 1.13.05, DCS-5030L, DCS-5020L, DCS-2530L, DCS-2630L, DCS-930L, DCS-932L, and DCS-932LB1.

Publication Date April 24, 2017, 7:59 p.m.
Registration Date Jan. 26, 2021, 1:29 p.m.
Last Update Nov. 21, 2024, 12:32 p.m.
Affected software configurations
Configuration1 or higher or less more than less than
cpe:2.3:o:dlink:dcs-2230l_firmware:*:*:*:*:*:*:*:* 1.03.01
execution environment
1 cpe:2.3:h:dlink:dcs-2230l:-:*:*:*:*:*:*:*
Configuration2 or higher or less more than less than
cpe:2.3:o:dlink:dcs-2310l_firmware:*:*:*:*:*:*:*:* 1.08.01
execution environment
1 cpe:2.3:h:dlink:dcs-2310l:-:*:*:*:*:*:*:*
Configuration3 or higher or less more than less than
cpe:2.3:o:dlink:dcs-2332l_firmware:*:*:*:*:*:*:*:* 1.08.01
execution environment
1 cpe:2.3:h:dlink:dcs-2332l:-:*:*:*:*:*:*:*
Configuration4 or higher or less more than less than
cpe:2.3:o:dlink:dcs-6010l_firmware:*:*:*:*:*:*:*:* 1.15.01
execution environment
1 cpe:2.3:h:dlink:dcs-6010l:-:*:*:*:*:*:*:*
Configuration5 or higher or less more than less than
cpe:2.3:o:dlink:dcs-7010l_firmware:*:*:*:*:*:*:*:* 1.08.01
execution environment
1 cpe:2.3:h:dlink:dcs-7010l:-:*:*:*:*:*:*:*
Configuration6 or higher or less more than less than
cpe:2.3:o:dlink:dcs-2530l_firmware:*:*:*:*:*:*:*:* 1.00.21
execution environment
1 cpe:2.3:h:dlink:dcs-2530l:-:*:*:*:*:*:*:*
Configuration7 or higher or less more than less than
cpe:2.3:o:dlink:dcs-930l_firmware:*:*:*:*:*:*:*:* 1.15.04
execution environment
1 cpe:2.3:h:dlink:dcs-930l:-:*:*:*:*:*:*:*
Configuration8 or higher or less more than less than
cpe:2.3:o:dlink:dcs-930l_firmware:*:*:*:*:*:*:*:* 2.13.15
execution environment
1 cpe:2.3:h:dlink:dcs-930l:-:*:*:*:*:*:*:*
Configuration9 or higher or less more than less than
cpe:2.3:o:dlink:dcs-932l_firmware:*:*:*:*:*:*:*:* 1.13.04
execution environment
1 cpe:2.3:h:dlink:dcs-932l:-:*:*:*:*:*:*:*
Configuration10 or higher or less more than less than
cpe:2.3:o:dlink:dcs-932l_firmware:*:*:*:*:*:*:*:* 2.13.15
execution environment
1 cpe:2.3:h:dlink:dcs-932l:-:*:*:*:*:*:*:*
Configuration11 or higher or less more than less than
cpe:2.3:o:dlink:dcs-934l_firmware:*:*:*:*:*:*:*:* 1.04.15
execution environment
1 cpe:2.3:h:dlink:dcs-934l:-:*:*:*:*:*:*:*
Configuration12 or higher or less more than less than
cpe:2.3:o:dlink:dcs-942l_firmware:*:*:*:*:*:*:*:* 1.27
execution environment
1 cpe:2.3:h:dlink:dcs-942l:-:*:*:*:*:*:*:*
Configuration13 or higher or less more than less than
cpe:2.3:o:dlink:dcs-942l_firmware:*:*:*:*:*:*:*:* 2.11.03
execution environment
1 cpe:2.3:h:dlink:dcs-942l:-:*:*:*:*:*:*:*
Configuration14 or higher or less more than less than
cpe:2.3:o:dlink:dcs-931l_firmware:*:*:*:*:*:*:*:* 1.13.05
execution environment
1 cpe:2.3:h:dlink:dcs-931l:-:*:*:*:*:*:*:*
Configuration15 or higher or less more than less than
cpe:2.3:o:dlink:dcs-933l_firmware:*:*:*:*:*:*:*:* 1.13.05
execution environment
1 cpe:2.3:h:dlink:dcs-933l:-:*:*:*:*:*:*:*
Configuration16 or higher or less more than less than
cpe:2.3:o:dlink:dcs-5009l_firmware:*:*:*:*:*:*:*:* 1.07.05
execution environment
1 cpe:2.3:h:dlink:dcs-5009l:-:*:*:*:*:*:*:*
Configuration17 or higher or less more than less than
cpe:2.3:o:dlink:dcs-5010l_firmware:*:*:*:*:*:*:*:* 1.13.05
execution environment
1 cpe:2.3:h:dlink:dcs-5010l:-:*:*:*:*:*:*:*
Configuration18 or higher or less more than less than
cpe:2.3:o:dlink:dcs-5020l_firmware:*:*:*:*:*:*:*:* 1.13.05
execution environment
1 cpe:2.3:h:dlink:dcs-5020l:-:*:*:*:*:*:*:*
Configuration19 or higher or less more than less than
cpe:2.3:o:dlink:dcs-5000l_firmware:*:*:*:*:*:*:*:* 1.02.02
execution environment
1 cpe:2.3:h:dlink:dcs-5000l:-:*:*:*:*:*:*:*
Configuration20 or higher or less more than less than
cpe:2.3:o:dlink:dcs-5025l_firmware:*:*:*:*:*:*:*:* 1.02.10
execution environment
1 cpe:2.3:h:dlink:dcs-5025l:-:*:*:*:*:*:*:*
Configuration21 or higher or less more than less than
cpe:2.3:o:dlink:dcs-5030l_firmware:*:*:*:*:*:*:*:* 1.01.06
execution environment
1 cpe:2.3:h:dlink:dcs-5030l:-:*:*:*:*:*:*:*
Configuration22 or higher or less more than less than
cpe:2.3:o:dlink:dcs-2210l_firmware:*:*:*:*:*:*:*:* 1.03.01
execution environment
1 cpe:2.3:h:dlink:dcs-2210l:-:*:*:*:*:*:*:*
Configuration23 or higher or less more than less than
cpe:2.3:o:dlink:dcs-2136l_firmware:*:*:*:*:*:*:*:* 1.04.01
execution environment
1 cpe:2.3:h:dlink:dcs-2136l:-:*:*:*:*:*:*:*
Configuration24 or higher or less more than less than
cpe:2.3:o:dlink:dcs-2132l_firmware:*:*:*:*:*:*:*:* 1.08.01
execution environment
1 cpe:2.3:h:dlink:dcs-2132l:-:*:*:*:*:*:*:*
Configuration25 or higher or less more than less than
cpe:2.3:o:dlink:dcs-7000l_firmware:*:*:*:*:*:*:*:* 1.04.00
execution environment
1 cpe:2.3:h:dlink:dcs-7000l:-:*:*:*:*:*:*:*
Configuration26 or higher or less more than less than
cpe:2.3:o:dlink:dcs-6212l_firmware:*:*:*:*:*:*:*:* 1.00.12
execution environment
1 cpe:2.3:h:dlink:dcs-6212l:-:*:*:*:*:*:*:*
Configuration27 or higher or less more than less than
cpe:2.3:o:dlink:dcs-5029l_firmware:*:*:*:*:*:*:*:* 1.12.00
execution environment
1 cpe:2.3:h:dlink:dcs-5029l:-:*:*:*:*:*:*:*
Configuration28 or higher or less more than less than
cpe:2.3:o:dlink:dcs-2310l_firmware:*:*:*:*:*:*:*:* 2.03.00
execution environment
1 cpe:2.3:h:dlink:dcs-2310l:-:*:*:*:*:*:*:*
Configuration29 or higher or less more than less than
cpe:2.3:o:dlink:dcs-2330l_firmware:*:*:*:*:*:*:*:* 1.13.00
execution environment
1 cpe:2.3:h:dlink:dcs-2330l:-:*:*:*:*:*:*:*
Configuration30 or higher or less more than less than
cpe:2.3:o:dlink:dcs-2132l_firmware:*:*:*:*:*:*:*:* 2.12.00
execution environment
1 cpe:2.3:h:dlink:dcs-2132l:-:*:*:*:*:*:*:*
Configuration31 or higher or less more than less than
cpe:2.3:o:dlink:dcs-5222l_firmware:*:*:*:*:*:*:*:* 2.12.00
execution environment
1 cpe:2.3:h:dlink:dcs-5222l:-:*:*:*:*:*:*:*
Related information, measures and tools
Common Vulnerabilities List