CVE-2013-3539
Last modified
CVE-2013-3539 is a vulnerability of currently unknown severity. Cross-site request forgery (CSRF) vulnerability in the command/user.cgi in Sony SNC CH140, SNC CH180, SNC CH240, SNC CH280, SNC DH140, SNC DH140T, SNC DH180, SNC DH240, SNC DH240T, SNC DH280, and possibly other camera models allows remote attackers to hijack the authentication of administrators for requests that add users.. EPSS estimates a 6.30% chance of exploitation in the next 30 days.
Description
Cross-site request forgery (CSRF) vulnerability in the command/user.cgi in Sony SNC CH140, SNC CH180, SNC CH240, SNC CH280, SNC DH140, SNC DH140T, SNC DH180, SNC DH240, SNC DH240T, SNC DH280, and possibly other camera models allows remote attackers to hijack the authentication of administrators for requests that add users.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ovislink | Airlive Wl2600cam | All versions |
| Sony | Snc Ch140 | All versions |
| Sony | Snc Ch180 | All versions |
| Sony | Snc Ch240 | All versions |
| Sony | Snc Ch280 | All versions |
| Sony | Snc Dh140 | All versions |
| Sony | Snc Dh140t | All versions |
| Sony | Snc Dh180 | All versions |
| Sony | Snc Dh240 | All versions |
| Sony | Snc Dh240t | All versions |
| Sony | Snc Dh280 | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-3539?
How severe is CVE-2013-3539?
How do I fix CVE-2013-3539?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2013
- CVE-2013-3533Multiple SQL injection vulnerabilities in Virtual Access Mon…
- CVE-2013-3534Cross-site scripting (XSS) vulnerability in the aiContactSaf…
- CVE-2013-3535Multiple cross-site scripting (XSS) vulnerabilities in CMSLo…
- CVE-2013-3536SQL injection vulnerability in the gp_LoadUserFromHash funct…
- CVE-2013-3537Multiple SQL injection vulnerabilities in todooforum.php in …
- CVE-2013-3538Multiple cross-site scripting (XSS) vulnerabilities in todoo…
- CVE-2013-3540Cross-site request forgery (CSRF) vulnerability in cgi-bin/a…
- CVE-2013-3541Directory traversal vulnerability in cgi-bin/admin/fileread …
- CVE-2013-3542Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD/LL, GXV3611…10
- CVE-2013-3543The AXIS Media Control (AMC) ActiveX control (AxisMediaContr…
- CVE-2013-3544Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2013-3550Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
Are you affected by CVE-2013-3539?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
