VulnerabilityModified
CVE-2023-41603
This allows attackers to arbitrarily access any services running on the device that may be inadvertently listening via IPv6.
MEDIUM 5.3EPSS 0.49%
Does this matter?
Lower severity and a low EPSS score (0.49%). Track it; it rarely justifies an emergency change on its own.
Description
D-Link R15 before v1.08.02 was discovered to contain no firewall restrictions for IPv6 traffic. This allows attackers to arbitrarily access any services running on the device that may be inadvertently listening via IPv6.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.49% probability · 41th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284
- Affected
- dlink/r15 firmware
- Source
- cve@mitre.org
References
- https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10347Patch, Vendor Advisory
- https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10347Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.