PT-2013-4469 · Sony · Snc Ch240+7
Jonás Ropero Castillo
·
Publicado
2013-10-01
·
Atualizado
2013-10-02
·
CVE-2013-3539
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Sony SNC CH140, SNC CH180, SNC CH240, SNC CH280, SNC DH140, SNC DH140T, SNC DH180, SNC DH240, SNC DH240T, SNC DH280 (affected versions not specified)
Description
A cross-site request forgery (CSRF) issue exists in the command/user.cgi of the affected Sony camera models. This allows remote attackers to hijack the authentication of administrators for requests that add users.
Recommendations
For Sony SNC CH140, SNC CH180, SNC CH240, SNC CH280, SNC DH140, SNC DH140T, SNC DH180, SNC DH240, SNC DH240T, SNC DH280, consider disabling access to the command/user.cgi until a patch is available.
Restrict access to the user addition functionality to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
CSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Snc Ch140
Snc Ch180
Snc Ch240
Snc Ch280
Snc Dh140
Snc Dh180
Snc Dh240
Snc Dh280