Lucene search

K
cve[email protected]CVE-2013-7204
HistoryJan 17, 2014 - 3:18 p.m.

CVE-2013-7204

2014-01-1715:18:02
CWE-352
web.nvd.nist.gov
22
cve-2013-7204
csrf
vulnerability
conceptronic
cipcamptiwl
camera
firmware
hijack
authentication
administrators
remote attackers
nvd

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.3 High

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

75.6%

Cross-site request forgery (CSRF) vulnerability in set_users.cgi in Conceptronic CIPCAMPTIWL Camera 1.0 with firmware 21.37.2.49 allows remote attackers to hijack the authentication of administrators for requests that add arbitrary users.

Affected configurations

NVD
Node
conceptroniccipcamptiwl_1.0_firmwareMatch21.37.2.49
AND
conceptroniccipcamptiwlMatch1.0

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.3 High

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

75.6%