Deep Sea Electronics DSE855 Factory Reset Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Deep Sea Electronics DSE855 devices. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the web-based UI. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-23173.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.zerodayinitiative.com/advisories/ZDI-24-675/ |
|
History
Wed, 07 Aug 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:h:deepseaelectronics:dse855:-:*:*:*:*:*:*:* |
Wed, 07 Aug 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Deepseaelectronics
Deepseaelectronics dse855 Deepseaelectronics dse855 Firmware |
|
| CPEs | cpe:2.3:h:deepseaelectronics:dse855:*:*:*:*:*:*:*:* cpe:2.3:o:deepseaelectronics:dse855_firmware:1.1.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Deepseaelectronics
Deepseaelectronics dse855 Deepseaelectronics dse855 Firmware |
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: zdi
Published: 2024-06-13T19:40:23.659Z
Updated: 2024-08-01T21:25:03.168Z
Reserved: 2024-06-13T02:02:23.578Z
Link: CVE-2024-5951
Updated: 2024-06-14T16:29:16.410Z
Status : Modified
Published: 2024-06-13T20:15:17.140
Modified: 2024-11-21T09:48:38.163
Link: CVE-2024-5951
No data.
ReportizFlow