PT-2013-4469 · Sony · Snc Ch240+7
Jonás Ropero Castillo
·
Published
2013-10-01
·
Updated
2013-10-02
·
CVE-2013-3539
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Sony SNC CH140, SNC CH180, SNC CH240, SNC CH280, SNC DH140, SNC DH140T, SNC DH180, SNC DH240, SNC DH240T, SNC DH280 (affected versions not specified)
Description
A cross-site request forgery (CSRF) issue exists in the command/user.cgi of the affected Sony camera models. This allows remote attackers to hijack the authentication of administrators for requests that add users.
Recommendations
For Sony SNC CH140, SNC CH180, SNC CH240, SNC CH280, SNC DH140, SNC DH140T, SNC DH180, SNC DH240, SNC DH240T, SNC DH280, consider disabling access to the command/user.cgi until a patch is available.
Restrict access to the user addition functionality to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Snc Ch140
Snc Ch180
Snc Ch240
Snc Ch280
Snc Dh140
Snc Dh180
Snc Dh240
Snc Dh280