Lucene search

K
cveMitreCVE-2013-2568
HistoryJan 29, 2020 - 6:15 p.m.

CVE-2013-2568

2020-01-2918:15:11
CWE-78
mitre
web.nvd.nist.gov
51
cve
command injection
zavio ip cameras
remote code execution
security vulnerability
nvd

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.6

Confidence

High

EPSS

0.917

Percentile

98.9%

A Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 via the ap parameter to /cgi-bin/mft/wireless_mft.cgi, which could let a remote malicious user execute arbitrary code.

Affected configurations

Nvd
Node
zaviof3105_firmwareRange1.6.03
AND
zaviof3105Match-
Node
zaviof312a_firmwareRange1.6.03
AND
zaviof312aMatch-
VendorProductVersionCPE
zaviof3105_firmware*cpe:2.3:o:zavio:f3105_firmware:*:*:*:*:*:*:*:*
zaviof3105-cpe:2.3:h:zavio:f3105:-:*:*:*:*:*:*:*
zaviof312a_firmware*cpe:2.3:o:zavio:f312a_firmware:*:*:*:*:*:*:*:*
zaviof312a-cpe:2.3:h:zavio:f312a:-:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.6

Confidence

High

EPSS

0.917

Percentile

98.9%