MEDIUM · 6.8

CVE-2013-3539

Cross-site request forgery (CSRF) vulnerability in the command/user.cgi in Sony SNC CH140, SNC CH180, SNC CH240, SNC CH280, SNC DH140, SNC DH140T, SNC DH180, SNC DH240, SNC DH240T, SNC DH280, and poss...

Vulnerability Description

Cross-site request forgery (CSRF) vulnerability in the command/user.cgi in Sony SNC CH140, SNC CH180, SNC CH240, SNC CH280, SNC DH140, SNC DH140T, SNC DH180, SNC DH240, SNC DH240T, SNC DH280, and possibly other camera models allows remote attackers to hijack the authentication of administrators for requests that add users.

CVSS Score

6.8

MEDIUM

AV:N/AC:M/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
OvislinkAirlive Wl2600Cam-
SonySnc Ch140-
SonySnc Ch180-
SonySnc Ch240-
SonySnc Ch280-
SonySnc Dh140-
SonySnc Dh140T-
SonySnc Dh180-
SonySnc Dh240-
SonySnc Dh240T-
SonySnc Dh280-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2013-3539?

CVE-2013-3539 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Cross-site request forgery (CSRF) vulnerability in the command/user.cgi in Sony SNC CH140, SNC CH180, SNC CH240, SNC CH280, SNC DH140, SNC DH140T, SNC DH180, SNC DH240, SNC DH240T, SNC DH280, and poss...

How severe is CVE-2013-3539?

CVE-2013-3539 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2013-3539?

Check the references section above for vendor advisories and patch information. Affected products include: Ovislink Airlive Wl2600Cam, Sony Snc Ch140, Sony Snc Ch180, Sony Snc Ch240, Sony Snc Ch280.