CVE-2013-3689

UnknownEPSS 1.48%

Last modified

CVE-2013-3689 is a vulnerability of currently unknown severity. Brickcom FB-100Ap, WCB-100Ap, MD-100Ap, WFB-100Ap, OB-100Ae, OSD-040E, and possibly other camera models with firmware 3.0.6.16C1 and earlier, do not properly restrict access to configfile.dump, which allow remote attackers to obtain sensitive information (user names, passwords, and configurations) via a get action.. EPSS estimates a 1.48% chance of exploitation in the next 30 days.

Description

Brickcom FB-100Ap, WCB-100Ap, MD-100Ap, WFB-100Ap, OB-100Ae, OSD-040E, and possibly other camera models with firmware 3.0.6.16C1 and earlier, do not properly restrict access to configfile.dump, which allow remote attackers to obtain sensitive information (user names, passwords, and configurations) via a get action.

Metrics

EPSS Probability
1.48%

70.6th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
Brickcom100ap Device Firmware<= 3.0.6.16c1
BrickcomFb-100apAll versions
BrickcomMd-100apAll versions
BrickcomOb-100aeAll versions
BrickcomOsd-040eAll versions
BrickcomWcb-100apAll versions
BrickcomWfb-100apAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2013-3689?
Brickcom FB-100Ap, WCB-100Ap, MD-100Ap, WFB-100Ap, OB-100Ae, OSD-040E, and possibly other camera models with firmware 3.0.6.16C1 and earlier, do not properly restrict access to configfile.dump, which allow remote attackers to obtain sensitive information (user names, passwords, and configurations) via a get action.
How severe is CVE-2013-3689?
Severity scoring for CVE-2013-3689 is pending analysis. The EPSS model estimates a 1.48% probability of exploitation in the next 30 days.
How do I fix CVE-2013-3689?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2013-3689?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST