Record summary

CVE-2022-34534 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

Digital Watchdog DW Spectrum Server 4.2.0.32842 allows attackers to access sensitive infromation via a crafted API call.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryHIGHDigital Watchdog DW Spectrum Server 4.2.0.32842 - Information DisclosureCVSS 7.5

Digital Watchdog DW Spectrum Server 4.2.0.32842 allows attackers to access sensitive infromation via a crafted API call.

Impact

Unauthenticated attackers can access sensitive system information including network configuration, remote addresses, and cloud host details through the moduleInformation API endpoint, potentially facilitating further attacks.

Remediation

Update Digital Watchdog DW Spectrum Server to a version newer than 4.2.0.32842 that requires authentication for the moduleInformation API endpoint.

WeaknessesCWE-200
Authorsritikchaddha
Template tagscvecve2022digital-watchdogdwspectrumexposurevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:o:dw:spectrum_server_firmware:4.2.0.32842:*:*:*:*:*:*:*
Shodan: http.favicon.hash:868509217
Shodan: http.favicon.hash:"868509217"
FOFA: icon_hash="868509217"

Source: ProjectDiscovery

References

2