Skip to main content
CRITICAL CISA KEV

CVE-2024-3272

CVSS v3

9.8

CRITICAL

EPSS Score

94.2 %

exploit probability

CISA KEV

Yes

known exploited

Exploitation

SSVC status

Description

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as very critical, has been found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. This issue affects some unknown processing of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET Request Handler. The manipulation of the argument user with the input messagebus leads to hard-coded credentials. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259283. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.

CISA Known Exploited Vulnerability

Date Added
2024-04-11
Patch Due Date
2024-05-02
Ransomware Use
Unknown

Technical details

Published
2024-04-04

Frequently asked questions

What is CVE-2024-3272?

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as very critical, has been found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. This issue affects some unknown processing of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET Request Handler. The manipulation of the argument user with the input messagebus leads to hard-coded credentials. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259283. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.

Is CVE-2024-3272 actively exploited?

Yes. CVE-2024-3272 is on the CISA Known Exploited Vulnerabilities (KEV) catalog, meaning it has been confirmed as actively exploited in the wild. CISA requires federal agencies to patch by 5/2/2024.

What is the CVSS score for CVE-2024-3272?

CVE-2024-3272 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2024-3272 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 30 free checks/month · Free API key