Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
D-Link DGS-1100-08PD Web boa.conf least privilege violation
Vulnerability Description
A vulnerability was identified in D-Link DGS-1100-08PD 1.00.006. This issue affects some unknown processing of the file /etc/boa.conf of the component Web Interface. Such manipulation leads to least privilege violation. The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is assessed as difficult. The exploit is publicly available and might be used.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Vulnerability Type
最小特权原则违背
Vulnerability Title
D-Link DGS-1100-08PD 安全漏洞
Vulnerability Description
D-Link DGS-1100-08PD是中国友讯(D-Link)公司的一款支持PoE供电的8端口千兆智能管理交换机。 D-Link DGS-1100-08PD 1.00.006版本存在安全漏洞,该漏洞源于Web Interface组件中/etc/boa.conf文件的未知处理操作不当,可能导致违反最小权限原则。攻击者可远程发起攻击。
CVSS Information
N/A
Vulnerability Type
N/A