Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2013-3539


Cross-site request forgery (CSRF) vulnerability in the command/user.cgi in Sony SNC CH140, SNC CH180, SNC CH240, SNC CH280, SNC DH140, SNC DH140T, SNC DH180, SNC DH240, SNC DH240T, SNC DH280, and possibly other camera models allows remote attackers to hijack the authentication of administrators for requests that add users.


Published

2013-10-01T19:55:03.507

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 6.8 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-352

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Hardware ovislink airlive_wl2600cam - Yes
Hardware sony snc_ch140 - Yes
Hardware sony snc_ch180 - Yes
Hardware sony snc_ch240 - Yes
Hardware sony snc_ch280 - Yes
Hardware sony snc_dh140 - Yes
Hardware sony snc_dh140t - Yes
Hardware sony snc_dh180 - Yes
Hardware sony snc_dh240 - Yes
Hardware sony snc_dh240t - Yes
Hardware sony snc_dh280 - Yes

References