CVE-2013-3539

UnknownEPSS 6.30%

Last modified

CVE-2013-3539 is a vulnerability of currently unknown severity. Cross-site request forgery (CSRF) vulnerability in the command/user.cgi in Sony SNC CH140, SNC CH180, SNC CH240, SNC CH280, SNC DH140, SNC DH140T, SNC DH180, SNC DH240, SNC DH240T, SNC DH280, and possibly other camera models allows remote attackers to hijack the authentication of administrators for requests that add users.. EPSS estimates a 6.30% chance of exploitation in the next 30 days.

Description

Cross-site request forgery (CSRF) vulnerability in the command/user.cgi in Sony SNC CH140, SNC CH180, SNC CH240, SNC CH280, SNC DH140, SNC DH140T, SNC DH180, SNC DH240, SNC DH240T, SNC DH280, and possibly other camera models allows remote attackers to hijack the authentication of administrators for requests that add users.

Metrics

EPSS Probability
6.30%

92.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
OvislinkAirlive Wl2600camAll versions
SonySnc Ch140All versions
SonySnc Ch180All versions
SonySnc Ch240All versions
SonySnc Ch280All versions
SonySnc Dh140All versions
SonySnc Dh140tAll versions
SonySnc Dh180All versions
SonySnc Dh240All versions
SonySnc Dh240tAll versions
SonySnc Dh280All versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2013-3539?
Cross-site request forgery (CSRF) vulnerability in the command/user.cgi in Sony SNC CH140, SNC CH180, SNC CH240, SNC CH280, SNC DH140, SNC DH140T, SNC DH180, SNC DH240, SNC DH240T, SNC DH280, and possibly other camera models allows remote attackers to hijack the authentication of administrators for requests that add users.
How severe is CVE-2013-3539?
Severity scoring for CVE-2013-3539 is pending analysis. The EPSS model estimates a 6.30% probability of exploitation in the next 30 days.
How do I fix CVE-2013-3539?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2013-3539?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST