6.8
CVSSv2

CVE-2013-3690

Published: 01/10/2013 Updated: 02/10/2013
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in cgi-bin/users.cgi in Brickcom FB-100Ap, WCB-100Ap, MD-100Ap, WFB-100Ap, OB-100Ae, OSD-040E, and possibly other camera models with firmware 3.1.0.8 and previous versions, allows remote malicious users to hijack the authentication of administrators for requests that add users.

Vulnerable Product Search on Vulmon Subscribe to Product

brickom 100ap_device_firmware 3.1.0.8

brickom wcb-100ap -

brickom wfb-100ap -

brickom ob-100ae -

brickom osd-040e -

brickom fb-100ap -

brickom md-100ap -

Exploits

source: wwwsecurityfocuscom/bid/60526/info Brickcom multiple IP cameras are prone to a cross-site request-forgery vulnerability Exploiting this issue may allow a remote attacker to perform certain unauthorized actions and gain access to the affected application Other attacks are also possible Brickcom cameras running firmware 3067 ...
Brickcom 100ap Series IP cameras suffer from authentication bypass and cross site request forgery vulnerabilities ...