CVE-2010-0593 Information

Description

The Cisco RVS4000 4-port Gigabit Security Router before 1.3.2.0 PVC2300 Business Internet Video Camera before 1.1.2.6 WVC200 Wireless-G PTZ Internet Video Camera before 1.1.1.15 WVC210 Wireless-G PTZ Internet Video Camera before 1.1.1.15 and WVC2300 Wireless-G Business Internet Video Camera before 1.1.2.6 do not properly restrict read access to passwords which allows context-dependent attackers to obtain sensitive information related to (1) access by remote authenticated users to a PVC2300 or WVC2300 via a crafted URL (2) leveraging setup privileges on a WVC200 or WVC210 and (3) leveraging administrative privileges on an RVS4000 aka Bug ID CSCte64726.

Reference

http://osvdb.org/63978 http://secunia.com/advisories/39510 http://www.cisco.com/en/US/products/products_security_advisory09186a0080b27511.shtml http://www.securityfocus.com/bid/39612 http://www.securitytracker.com/id?1023906 http://www.vupen.com/english/advisories/2010/0965 https://exchange.xforce.ibmcloud.com/vulnerabilities/58034

Share on: