CVE-2010-0593

Cisco PVC2300 < 1.1.2.6 - Authenticated Password Disclosure via Crafted URL

Title source: llm
STIX 2.1

Description

The Cisco RVS4000 4-port Gigabit Security Router before 1.3.2.0, PVC2300 Business Internet Video Camera before 1.1.2.6, WVC200 Wireless-G PTZ Internet Video Camera before 1.1.1.15, WVC210 Wireless-G PTZ Internet Video Camera before 1.1.1.15, and WVC2300 Wireless-G Business Internet Video Camera before 1.1.2.6 do not properly restrict read access to passwords, which allows context-dependent attackers to obtain sensitive information, related to (1) access by remote authenticated users to a PVC2300 or WVC2300 via a crafted URL, (2) leveraging setup privileges on a WVC200 or WVC210, and (3) leveraging administrative privileges on an RVS4000, aka Bug ID CSCte64726.

References (7)

Core 7
Core References
Patch, Vendor Advisory vendor-advisory x_refsource_cisco
http://www.cisco.com/en/US/products/products_security_advisory09186a0080b27511.shtml
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1023906
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/58034
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/0965
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/63978
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/39612
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/39510

Scores

EPSS 0.0302
EPSS Percentile 86.1%

Details

CWE
CWE-264
Status published
Products (8)
cisco/pvc2300 < 1.1.1.4
cisco/rvs4000 1.3.0.5
cisco/rvs4000 < 1.3.1.0
cisco/wvc200 1.1.0.12
cisco/wvc200 < 1.1.0.15
cisco/wvc210 1.1.0.12
cisco/wvc210 < 1.1.0.15
cisco/wvc2300 < 1.1.1.4
Published Apr 22, 2010
Tracked Since Feb 18, 2026