PT-2013-4469 · Sony · Snc Ch240+7

Jonás Ropero Castillo

·

Published

2013-10-01

·

Updated

2013-10-02

·

CVE-2013-3539

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Sony SNC CH140, SNC CH180, SNC CH240, SNC CH280, SNC DH140, SNC DH140T, SNC DH180, SNC DH240, SNC DH240T, SNC DH280 (affected versions not specified)
Description A cross-site request forgery (CSRF) issue exists in the command/user.cgi of the affected Sony camera models. This allows remote attackers to hijack the authentication of administrators for requests that add users.
Recommendations For Sony SNC CH140, SNC CH180, SNC CH240, SNC CH280, SNC DH140, SNC DH140T, SNC DH180, SNC DH240, SNC DH240T, SNC DH280, consider disabling access to the command/user.cgi until a patch is available. Restrict access to the user addition functionality to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-3539

Affected Products

Snc Ch140
Snc Ch180
Snc Ch240
Snc Ch280
Snc Dh140
Snc Dh180
Snc Dh240
Snc Dh280