5
CVSSv2

CVE-2013-3585

Published: 28/08/2013 Updated: 07/10/2013
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Samsung Web Viewer for Samsung DVR devices stores credentials in cleartext, which allows context-dependent malicious users to obtain sensitive information via vectors involving (1) direct access to a file or (2) the user-setup web page.

Vulnerable Product Search on Vulmon Subscribe to Product

samsung smart_viewer -

Exploits

************************************************************** Title: Samsung DVR authentication bypass Version affected: firmware version <= 110 Vendor: Samsung - wwwsamsung-securitycom Discovered by: Andrea Fabrizi Email: andreafabrizi@gmailcom Web: wwwandreafabriziit Twitter: @andreaf83 Status: unpatched ************************ ...