CVE-2024-9535
published 2024-10-05CVE-2024-9535: A vulnerability was found in D-Link DIR-605L 2.13B01 BETA. It has been declared as critical. Affected by this vulnerability is the function…
PriorityP262high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.59%
72.9th percentile
A vulnerability was found in D-Link DIR-605L 2.13B01 BETA. It has been declared as critical. Affected by this vulnerability is the function formEasySetupWWConfig of the file /goform/formEasySetupWWConfig. The manipulation of the argument curTime leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | nifi | — | — |
| d-link | dir-605l | — | — |
| dlink | dir-605l_firmware | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_apache2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j236-j3xx-3rr2: A vulnerability was found in D-Link DIR-605L 2
ghsa_unreviewed·2024-10-05
CVE-2024-9535 [HIGH] CWE-120 GHSA-j236-j3xx-3rr2: A vulnerability was found in D-Link DIR-605L 2
A vulnerability was found in D-Link DIR-605L 2.13B01 BETA. It has been declared as critical. Affected by this vulnerability is the function formEasySetupWWConfig of the file /goform/formEasySetupWWConfig. The manipulation of the argument curTime leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Apache
Apache nifi: CVE-2024-56512
vendor_apache·CVSS 2.1
CVE-2024-56512 [LOW] Apache nifi: CVE-2024-56512
Apache nifi: CVE-2024-56512
Title: Missing Complete Authorization for Parameter and Service References Published: 2024-12-27 Severity: Low Products: Apache NiFi Affected Versions: 1.10.0 to 2.0.0 Fixed Versions: 2.1.0 Reporter: Matt Gilman References CVE Record: CVE-2024-56512 NVD Record: CVE-2024-56512 Apache Jira Issue: NIFI-13976 GitHub Pull Request: 9535 Apache NiFi 1.10.0 through 2.0.0 are missing fine-grained authorization checking for Parameter Contexts, referenced Controller Services, and referenced Parameter Providers, when creating new Process Groups. Creating a new Process Group can include binding to a Parameter Context, but in cases where the Process Group did not reference any Parameter values, the framework did not check user authorization for the bound Parameter Context. Mi
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-10-05
Published