CVE-2010-0593
Last modified
CVE-2010-0593 is a vulnerability of currently unknown severity. The Cisco RVS4000 4-port Gigabit Security Router before 1.3.2.0, PVC2300 Business Internet Video Camera before 1.1.2.6, WVC200 Wireless-G PTZ Internet Video Camera before 1.1.1.15, WVC210 Wireless-G PTZ Internet Video Camera before 1.1.1.15, and WVC2300 Wireless-G Business Internet Video Camera before 1.1.2.6 do not properly restrict read access to passwords, which allows context-dependent attackers to obtain sensitive information, related to (1) access by remote authenticated users to a PVC2300 or WVC2300 via a crafted URL, (2) leveraging setup privileges on a WVC200 or WVC210, and (3) leveraging administrative privileges on an RVS4000, aka Bug ID CSCte64726.. EPSS estimates a 3.02% chance of exploitation in the next 30 days.
Description
The Cisco RVS4000 4-port Gigabit Security Router before 1.3.2.0, PVC2300 Business Internet Video Camera before 1.1.2.6, WVC200 Wireless-G PTZ Internet Video Camera before 1.1.1.15, WVC210 Wireless-G PTZ Internet Video Camera before 1.1.1.15, and WVC2300 Wireless-G Business Internet Video Camera before 1.1.2.6 do not properly restrict read access to passwords, which allows context-dependent attackers to obtain sensitive information, related to (1) access by remote authenticated users to a PVC2300 or WVC2300 via a crafted URL, (2) leveraging setup privileges on a WVC200 or WVC210, and (3) leveraging administrative privileges on an RVS4000, aka Bug ID CSCte64726.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Pvc2300 | <= 1.1.1.4 |
| Cisco | Wvc200 | <= 1.1.0.15 |
| Cisco | Wvc200 | 1.1.0.12 |
| Cisco | Wvc210 | <= 1.1.0.15 |
| Cisco | Wvc210 | 1.1.0.12 |
| Cisco | Wvc2300 | <= 1.1.1.4 |
| Cisco | Rvs4000 | <= 1.3.1.0 |
| Cisco | Rvs4000 | 1.3.0.5 |
References
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080b27511.shtmlPatch, Vendor Advisory
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080b27511.shtmlPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-0593?
How severe is CVE-2010-0593?
How do I fix CVE-2010-0593?
Are you affected by CVE-2010-0593?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
