{"cve":"CVE-2023-5074","epss":{"score":0.69555},"mitre":{"cpes":[],"created":"2023-09-20T15:32:44.451000+00:00","description":"Use of a static key to protect a JWT token used in user authentication can allow an for an authentication bypass in D-Link D-View 8 v2.0.1.28","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"cvssV4_0":{}},"mitre_repo_path":"cves/2023/5xxx/CVE-2023-5074.json","references":["https://www.tenable.com/security/research/tra-2023-32"],"title":"Authentication Bypass in D-Link D-View 8","updated":"2024-09-24T15:26:54.056000+00:00","vendors":[],"weaknesses":["CWE-798"]},"nvd":{"cpes":["cpe:2.3:a:dlink:d-view_8:2.0.1.28:*:*:*:*:*:*:*"],"created":"2023-09-20T16:15:12.750000+00:00","description":"Use of a static key to protect a JWT token used in user authentication can allow an for an authentication bypass in D-Link D-View 8 v2.0.1.28","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"cvssV4_0":{}},"nvd_repo_path":"2023/CVE-2023-5074.json","references":["https://www.tenable.com/security/research/tra-2023-32"],"title":null,"updated":"2026-06-17T06:47:28.883000+00:00","vendors":["dlink","dlink$PRODUCT$d-view_8"],"weaknesses":["CWE-798"]},"opencve":{"changes":[{"created":"2024-09-24T16:30:00+00:00","data":[{"details":{"added":{"ssvc":{"options":{"Automatable":"yes","Exploitation":"poc","Technical Impact":"total"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"cb0d4808-59a4-41a3-8f29-fb9fc5d89668"},{"created":"2025-07-16T13:45:00+00:00","data":[{"details":{"added":{},"removed":{},"updated":{"epss":{"new":{"score":0.92231},"old":{"score":0.92341}}}},"type":"metrics"}],"id":"bec58515-7b9d-4571-8af9-fd30b90348ce"}],"cpes":{"data":["cpe:2.3:a:dlink:d-view_8:2.0.1.28:*:*:*:*:*:*:*"],"providers":["nvd","vulnrichment"]},"created":{"data":"2023-09-20T15:32:44.451000+00:00","provider":"mitre"},"description":{"data":"Use of a static key to protect a JWT token used in user authentication can allow an for an authentication bypass in D-Link D-View 8 v2.0.1.28","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"provider":"mitre"},"cvssV4_0":{"data":{},"provider":null},"epss":{"data":{"score":0.69555},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"yes","Exploitation":"poc","Technical Impact":"total"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://www.tenable.com/security/research/tra-2023-32"],"providers":["mitre","nvd"]},"title":{"data":"Authentication Bypass in D-Link D-View 8","provider":"mitre"},"updated":{"data":"2024-11-21T08:41:00.840000+00:00","provider":"nvd"},"vendors":{"data":["dlink","dlink$PRODUCT$d-view_8"],"providers":["nvd","vulnrichment"]},"weaknesses":{"data":["CWE-798"],"providers":["mitre","nvd"]}},"vulnrichment":{"cpes":["cpe:2.3:a:dlink:d-view_8:2.0.1.28:*:*:*:*:*:*:*"],"created":"2023-09-20T15:32:44.451000+00:00","description":"Use of a static key to protect a JWT token used in user authentication can allow an for an authentication bypass in D-Link D-View 8 v2.0.1.28","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"yes","Exploitation":"poc","Technical Impact":"total"},"version":"2.0.3"}},"references":[],"title":"Authentication Bypass in D-Link D-View 8","updated":"2024-09-24T15:26:48.765000+00:00","vendors":["dlink","dlink$PRODUCT$d-view_8"],"vulnrichment_repo_path":"2023/5xxx/CVE-2023-5074.json","weaknesses":[]}}