PT-2020-7361 · Tesco+1 · Dcs-2121+13

Francisco Falcon

+1

·

Published

2020-01-28

·

Updated

2021-04-26

·

CVE-2013-1601

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: D-LINK WCS-1100 version 1.02 TESCO DCS-2121 version 1.05 TESCO TESCO DCS-2102 version 1.05 TESCO D-LINK DCS-7510 version 1.00 D-LINK DCS-7410 version 1.00 D-LINK DCS-6410 version 1.00 D-LINK DCS-5635 version 1.01 D-LINK DCS-5605 version 1.01 D-LINK DCS-5230L version 1.02 D-LINK DCS-5230 version 1.02 D-LINK DCS-3430 version 1.02 D-LINK DCS-3411 version 1.02 D-LINK DCS-3410 version 1.02 D-LINK DCS-2121 versions 1.05 RU through 1.06 FR D-LINK DCS-2121 versions 1.05 RU through 1.06 D-LINK DCS-2102 versions 1.05 RU through 1.06 FR D-LINK DCS-2102 versions 1.05 RU through 1.06 D-LINK DCS-1130L version 1.04 D-LINK DCS-1130 versions 1.03 through 1.04 US D-LINK DCS-1100L version 1.04 D-LINK DCS-1100 versions 1.03 through 1.04 US
Description: An Information Disclosure issue exists due to a failure to restrict access on the lums.cgi script when processing a live video stream, which could let a malicious user obtain sensitive information.
Recommendations: For D-LINK WCS-1100 version 1.02, restrict access to the lums.cgi script. For TESCO DCS-2121 version 1.05 TESCO, restrict access to the lums.cgi script. For TESCO DCS-2102 version 1.05 TESCO, restrict access to the lums.cgi script. For D-LINK DCS-7510 version 1.00, restrict access to the lums.cgi script. For D-LINK DCS-7410 version 1.00, restrict access to the lums.cgi script. For D-LINK DCS-6410 version 1.00, restrict access to the lums.cgi script. For D-LINK DCS-5635 version 1.01, restrict access to the lums.cgi script. For D-LINK DCS-5605 version 1.01, restrict access to the lums.cgi script. For D-LINK DCS-5230L version 1.02, restrict access to the lums.cgi script. For D-LINK DCS-5230 version 1.02, restrict access to the lums.cgi script. For D-LINK DCS-3430 version 1.02, restrict access to the lums.cgi script. For D-LINK DCS-3411 version 1.02, restrict access to the lums.cgi script. For D-LINK DCS-3410 version 1.02, restrict access to the lums.cgi script. For D-LINK DCS-2121 versions 1.05 RU through 1.06 FR, restrict access to the lums.cgi script. For D-LINK DCS-2121 versions 1.05 RU through 1.06, restrict access to the lums.cgi script. For D-LINK DCS-2102 versions 1.05 RU through 1.06 FR, restrict access to the lums.cgi script. For D-LINK DCS-2102 versions 1.05 RU through 1.06, restrict access to the lums.cgi script. For D-LINK DCS-1130L version 1.04, restrict access to the lums.cgi script. For D-LINK DCS-1130 versions 1.03 through 1.04 US, restrict access to the lums.cgi script. For D-LINK DCS-1100L version 1.04, restrict access to the lums.cgi script. For D-LINK DCS-1100 versions 1.03 through 1.04 US, restrict access to the lums.cgi script.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-1601

Affected Products

Dcs-1100L
Dcs-1130
Dcs-2102
Dcs-2121
Dcs-3410
Dcs-3411
Dcs-3430
Dcs-5230
Dcs-5605
Dcs-5635
Dcs-6410
Dcs-7410
Dcs-7510
Wcs-1100