9
CVSSv2

CVE-2010-0593

Published: 22/04/2010 Updated: 17/08/2017
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

The Cisco RVS4000 4-port Gigabit Security Router prior to 1.3.2.0, PVC2300 Business Internet Video Camera prior to 1.1.2.6, WVC200 Wireless-G PTZ Internet Video Camera prior to 1.1.1.15, WVC210 Wireless-G PTZ Internet Video Camera prior to 1.1.1.15, and WVC2300 Wireless-G Business Internet Video Camera prior to 1.1.2.6 do not properly restrict read access to passwords, which allows context-dependent malicious users to obtain sensitive information, related to (1) access by remote authenticated users to a PVC2300 or WVC2300 via a crafted URL, (2) leveraging setup privileges on a WVC200 or WVC210, and (3) leveraging administrative privileges on an RVS4000, aka Bug ID CSCte64726.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco pvc2300

cisco wvc200 1.1.0.12

cisco wvc200

cisco wvc210 1.1.0.12

cisco wvc210

cisco wvc2300

cisco rvs4000

cisco rvs4000 1.3.0.5

Vendor Advisories

Cisco Small Business Video Surveillance Cameras and Cisco RVS4000 4-port Gigabit Security Routers contain a vulnerability that could allow an authenticated user to view passwords for other users, regardless of the authenticated user's level of authorization An unprivileged user could take advantage of this vulnerability to gain f ...