CVE-2013-3690
medium · 6.8Cross-site request forgery (CSRF) vulnerability in cgi-bin/users.cgi in Brickcom FB-100Ap, WCB-100Ap, MD-100Ap, WFB-100Ap, OB-100Ae, OSD-040E, and possibly other camera models with firmware 3.1.0.8 and earlier, allows remote attackers to hijack the authentication of administrators for requests that add users.
6.8
CVSS
12.4%
EPSS (exploit prob.)
96th
EPSS percentile
2013-10-01
Published
AV:N/AC:M/Au:N/C:P/I:P/A:P
Weaknesses
CWE-352
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| brickcom | 100ap_device_firmware | 3.1.0.8 |
| brickcom | fb-100ap | all versions |
| brickcom | md-100ap | all versions |
| brickcom | ob-100ae | all versions |
| brickcom | osd-040e | all versions |
| brickcom | wcb-100ap | all versions |
| brickcom | wfb-100ap | all versions |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2013-3690