6.8

CVE-2013-3539

Exploit
Cross-site request forgery (CSRF) vulnerability in the command/user.cgi in Sony SNC CH140, SNC CH180, SNC CH240, SNC CH280, SNC DH140, SNC DH140T, SNC DH180, SNC DH240, SNC DH240T, SNC DH280, and possibly other camera models allows remote attackers to hijack the authentication of administrators for requests that add users.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ovislink ≫ Airlive Wl2600cam Version -
Sony ≫ Snc Ch140 Version -
Sony ≫ Snc Ch180 Version -
Sony ≫ Snc Ch240 Version -
Sony ≫ Snc Ch280 Version -
Sony ≫ Snc Dh140 Version -
Sony ≫ Snc Dh140t Version -
Sony ≫ Snc Dh180 Version -
Sony ≫ Snc Dh240 Version -
Sony ≫ Snc Dh240t Version -
Sony ≫ Snc Dh280 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 8.76% 0.946
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.