PT-2013-4763 · Grandstream · Grandstream Gxv3601+8

Jonás Ropero Castillo

·

Published

2013-10-01

·

Updated

2013-10-02

·

CVE-2013-3963

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Grandstream GXV3501 versions (affected versions not specified) Grandstream GXV3504 versions (affected versions not specified) Grandstream GXV3601 versions (affected versions not specified) Grandstream GXV3601HD/LL versions (affected versions not specified) Grandstream GXV3611HD/LL versions (affected versions not specified) Grandstream GXV3615W/P versions (affected versions not specified) Grandstream GXV3651FHD versions (affected versions not specified) Grandstream GXV3662HD versions (affected versions not specified) Grandstream GXV3615WP HD versions (affected versions not specified) Grandstream GXV3500 versions (affected versions not specified)
Description A cross-site request forgery (CSRF) issue exists in the goform/usermanage endpoint of Grandstream camera models, allowing remote attackers to hijack the authentication of victims for requests that add users.
Recommendations For Grandstream GXV3501, consider disabling the goform/usermanage endpoint until a patch is available. For Grandstream GXV3504, restrict access to the goform/usermanage endpoint to minimize the risk of exploitation. For Grandstream GXV3601, avoid using the goform/usermanage endpoint until the issue is resolved. For Grandstream GXV3601HD/LL, GXV3611HD/LL, GXV3615W/P, GXV3651FHD, GXV3662HD, GXV3615WP HD, and GXV3500, at the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-3963

Affected Products

Grandstream Gxv3500
Grandstream Gxv3501
Grandstream Gxv3504
Grandstream Gxv3601
Grandstream Gxv3601Hd/Ll
Grandstream Gxv3611Hd/Ll
Grandstream Gxv3615W/P
Grandstream Gxv3651Fhd
Grandstream Gxv3662Hd