HIGH · 7.8

CVE-2013-3689

Brickcom FB-100Ap, WCB-100Ap, MD-100Ap, WFB-100Ap, OB-100Ae, OSD-040E, and possibly other camera models with firmware 3.0.6.16C1 and earlier, do not properly restrict access to configfile.dump, which ...

Vulnerability Description

Brickcom FB-100Ap, WCB-100Ap, MD-100Ap, WFB-100Ap, OB-100Ae, OSD-040E, and possibly other camera models with firmware 3.0.6.16C1 and earlier, do not properly restrict access to configfile.dump, which allow remote attackers to obtain sensitive information (user names, passwords, and configurations) via a get action.

CVSS Score

7.8

HIGH

AV:N/AC:L/Au:N/C:C/I:N/A:N
Confidentiality
COMPLETE
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
Brickcom100Ap Device Firmware<= 3.0.6.16c1
BrickcomFb-100Ap-
BrickcomMd-100Ap-
BrickcomOb-100Ae-
BrickcomOsd-040E-
BrickcomWcb-100Ap-
BrickcomWfb-100Ap-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2013-3689?

CVE-2013-3689 is a vulnerability with a CVSS score of 7.8 (HIGH). Brickcom FB-100Ap, WCB-100Ap, MD-100Ap, WFB-100Ap, OB-100Ae, OSD-040E, and possibly other camera models with firmware 3.0.6.16C1 and earlier, do not properly restrict access to configfile.dump, which ...

How severe is CVE-2013-3689?

CVE-2013-3689 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2013-3689?

Check the references section above for vendor advisories and patch information. Affected products include: Brickcom 100Ap Device Firmware, Brickcom Fb-100Ap, Brickcom Md-100Ap, Brickcom Ob-100Ae, Brickcom Osd-040E.