PT-2013-4763 · Grandstream · Grandstream Gxv3601+8
Jonás Ropero Castillo
·
Published
2013-10-01
·
Updated
2013-10-02
·
CVE-2013-3963
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Grandstream GXV3501 versions (affected versions not specified)
Grandstream GXV3504 versions (affected versions not specified)
Grandstream GXV3601 versions (affected versions not specified)
Grandstream GXV3601HD/LL versions (affected versions not specified)
Grandstream GXV3611HD/LL versions (affected versions not specified)
Grandstream GXV3615W/P versions (affected versions not specified)
Grandstream GXV3651FHD versions (affected versions not specified)
Grandstream GXV3662HD versions (affected versions not specified)
Grandstream GXV3615WP HD versions (affected versions not specified)
Grandstream GXV3500 versions (affected versions not specified)
Description
A cross-site request forgery (CSRF) issue exists in the goform/usermanage endpoint of Grandstream camera models, allowing remote attackers to hijack the authentication of victims for requests that add users.
Recommendations
For Grandstream GXV3501, consider disabling the goform/usermanage endpoint until a patch is available.
For Grandstream GXV3504, restrict access to the goform/usermanage endpoint to minimize the risk of exploitation.
For Grandstream GXV3601, avoid using the goform/usermanage endpoint until the issue is resolved.
For Grandstream GXV3601HD/LL, GXV3611HD/LL, GXV3615W/P, GXV3651FHD, GXV3662HD, GXV3615WP HD, and GXV3500, at the moment, there is no information about a newer version that contains a fix for this issue.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grandstream Gxv3500
Grandstream Gxv3501
Grandstream Gxv3504
Grandstream Gxv3601
Grandstream Gxv3601Hd/Ll
Grandstream Gxv3611Hd/Ll
Grandstream Gxv3615W/P
Grandstream Gxv3651Fhd
Grandstream Gxv3662Hd