CVE-2013-2570 Information
Feb 14, 2021
cve
Description
A Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 in the General.Time.NTP.Server parameter to the sub_C8C8 function of the binary /opt/cgi/view/param which could let a remove malicious user execute arbitrary code.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
http://www.securityfocus.com/bid/60188 https://exchange.xforce.ibmcloud.com/vulnerabilities/84567 https://packetstormsecurity.com/files/cve/CVE-2013-2570 https://www.coresecurity.com/advisories/zavio-ip-cameras-multiple-vulnerabilities
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: