PT-2010-2350 · Cisco · Rvs4000+4
Published
2010-04-22
·
Updated
2017-08-17
·
CVE-2010-0593
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco RVS4000 versions prior to 1.3.2.0
Cisco PVC2300 Business Internet Video Camera versions prior to 1.1.2.6
Cisco WVC200 Wireless-G PTZ Internet Video Camera versions prior to 1.1.1.15
Cisco WVC210 Wireless-G PTZ Internet Video Camera versions prior to 1.1.1.15
Cisco WVC2300 Wireless-G Business Internet Video Camera versions prior to 1.1.2.6
Description
The issue allows context-dependent attackers to obtain sensitive information due to improper restriction of read access to passwords. This can be achieved through various means, including access by remote authenticated users to certain devices via a crafted URL, leveraging setup privileges on specific devices, or leveraging administrative privileges on the RVS4000.
Recommendations
For Cisco RVS4000 versions prior to 1.3.2.0, update to version 1.3.2.0 or later.
For Cisco PVC2300 Business Internet Video Camera versions prior to 1.1.2.6, update to version 1.1.2.6 or later.
For Cisco WVC200 Wireless-G PTZ Internet Video Camera versions prior to 1.1.1.15, update to version 1.1.1.15 or later.
For Cisco WVC210 Wireless-G PTZ Internet Video Camera versions prior to 1.1.1.15, update to version 1.1.1.15 or later.
For Cisco WVC2300 Wireless-G Business Internet Video Camera versions prior to 1.1.2.6, update to version 1.1.2.6 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pvc2300 Business Internet Video Camera
Rvs4000
Wvc200 Wireless-G Ptz Internet Video Camera
Wvc210 Wireless-G Ptz Internet Video Camera
Wvc2300 Wireless-G Business Internet Video Camera