Deep Sea Electronics DSE855 Restart Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Deep Sea Electronics DSE855 devices. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the web-based UI. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-23174.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.zerodayinitiative.com/advisories/ZDI-24-676/ |
History
Wed, 07 Aug 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Deepseaelectronics
Deepseaelectronics dse855 Deepseaelectronics dse855 Firmware |
|
CPEs | cpe:2.3:h:deepseaelectronics:dse855:-:*:*:*:*:*:*:* cpe:2.3:o:deepseaelectronics:dse855_firmware:1.1.0:*:*:*:*:*:*:* |
|
Vendors & Products |
Deepseaelectronics
Deepseaelectronics dse855 Deepseaelectronics dse855 Firmware |
|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: zdi
Published: 2024-06-13T19:40:19.388Z
Updated: 2024-08-01T21:25:02.972Z
Reserved: 2024-06-13T02:02:30.282Z
Link: CVE-2024-5952
Vulnrichment
Updated: 2024-06-17T16:35:56.429Z
NVD
Status : Modified
Published: 2024-06-13T20:15:17.350
Modified: 2024-11-21T09:48:38.283
Link: CVE-2024-5952
Redhat
No data.