Vulnerability Description
Brickcom FB-100Ap, WCB-100Ap, MD-100Ap, WFB-100Ap, OB-100Ae, OSD-040E, and possibly other camera models with firmware 3.0.6.16C1 and earlier, do not properly restrict access to configfile.dump, which allow remote attackers to obtain sensitive information (user names, passwords, and configurations) via a get action.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Brickcom | 100Ap Device Firmware | <= 3.0.6.16c1 |
| Brickcom | Fb-100Ap | - |
| Brickcom | Md-100Ap | - |
| Brickcom | Ob-100Ae | - |
| Brickcom | Osd-040E | - |
| Brickcom | Wcb-100Ap | - |
| Brickcom | Wfb-100Ap | - |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2013-3689?
CVE-2013-3689 is a vulnerability with a CVSS score of 7.8 (HIGH). Brickcom FB-100Ap, WCB-100Ap, MD-100Ap, WFB-100Ap, OB-100Ae, OSD-040E, and possibly other camera models with firmware 3.0.6.16C1 and earlier, do not properly restrict access to configfile.dump, which ...
How severe is CVE-2013-3689?
CVE-2013-3689 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-3689?
Check the references section above for vendor advisories and patch information. Affected products include: Brickcom 100Ap Device Firmware, Brickcom Fb-100Ap, Brickcom Md-100Ap, Brickcom Ob-100Ae, Brickcom Osd-040E.