Vulnerability Description
Cross-site request forgery (CSRF) vulnerability in cgi-bin/users.cgi in Brickcom FB-100Ap, WCB-100Ap, MD-100Ap, WFB-100Ap, OB-100Ae, OSD-040E, and possibly other camera models with firmware 3.1.0.8 and earlier, allows remote attackers to hijack the authentication of administrators for requests that add users.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Brickcom | 100Ap Device Firmware | 3.1.0.8 |
| Brickcom | Fb-100Ap | - |
| Brickcom | Md-100Ap | - |
| Brickcom | Ob-100Ae | - |
| Brickcom | Osd-040E | - |
| Brickcom | Wcb-100Ap | - |
| Brickcom | Wfb-100Ap | - |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2013-3690?
CVE-2013-3690 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Cross-site request forgery (CSRF) vulnerability in cgi-bin/users.cgi in Brickcom FB-100Ap, WCB-100Ap, MD-100Ap, WFB-100Ap, OB-100Ae, OSD-040E, and possibly other camera models with firmware 3.1.0.8 an...
How severe is CVE-2013-3690?
CVE-2013-3690 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-3690?
Check the references section above for vendor advisories and patch information. Affected products include: Brickcom 100Ap Device Firmware, Brickcom Fb-100Ap, Brickcom Md-100Ap, Brickcom Ob-100Ae, Brickcom Osd-040E.