HIGH · 7.5

CVE-2013-1602

An Information Disclosure vulnerability exists due to insufficient validation of authentication cookies for the RTSP session in D-Link DCS-5635 1.01, DCS-1100L 1.04, DCS-1130L 1.04, DCS-1100 1.03/1.04...

Vulnerability Description

An Information Disclosure vulnerability exists due to insufficient validation of authentication cookies for the RTSP session in D-Link DCS-5635 1.01, DCS-1100L 1.04, DCS-1130L 1.04, DCS-1100 1.03/1.04_US, DCS-1130 1.03/1.04_US , DCS-2102 1.05_RU/1.06/1.06_FR/1.05_TESCO, DCS-2121 1.05_RU/1.06/1.06_FR/1.05_TESCO, DCS-3410 1.02, DCS-5230 1.02, DCS-5230L 1.02, DCS-6410 1.0, DCS-7410 1.0, DCS-7510 1.0, and WCS-1100 1.02, which could let a malicious user obtain unauthorized access to video streams.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
DlinkDcs-3411 Firmware1.02
DlinkDcs-3411-
DlinkDcs-3430 Firmware1.02
DlinkDcs-3430-
DlinkDcs-5605 Firmware1.01
DlinkDcs-5605-
DlinkDcs-5635 Firmware1.01
DlinkDcs-5635-
DlinkDcs-1100L Firmware1.04
DlinkDcs-1100L-
DlinkDcs-1130L Firmware1.04
DlinkDcs-1130L-
DlinkDcs-1100 Firmware1.03
DlinkDcs-1100-
DlinkDcs-1130 Firmware1.03
DlinkDcs-1130-
DlinkDcs-2102 Firmware1.05
DlinkDcs-2102-
DlinkDcs-2121 Firmware1.05
DlinkDcs-2121-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2013-1602?

CVE-2013-1602 is a vulnerability with a CVSS score of 7.5 (HIGH). An Information Disclosure vulnerability exists due to insufficient validation of authentication cookies for the RTSP session in D-Link DCS-5635 1.01, DCS-1100L 1.04, DCS-1130L 1.04, DCS-1100 1.03/1.04...

How severe is CVE-2013-1602?

CVE-2013-1602 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2013-1602?

Check the references section above for vendor advisories and patch information. Affected products include: Dlink Dcs-3411 Firmware, Dlink Dcs-3411, Dlink Dcs-3430 Firmware, Dlink Dcs-3430, Dlink Dcs-5605 Firmware.