imPC@ndo IT

Tracker / CVE-2010-0593

CVE-2010-0593

High 9.0

The Cisco RVS4000 4-port Gigabit Security Router before 1.3.2.0, PVC2300 Business Internet Video Camera before 1.1.2.6, WVC200 Wireless-G PTZ Internet Video Camera before 1.1.1.15, WVC210 Wireless-G PTZ Internet Video Camera before 1.1.1.15, and WVC2300 Wireless-G Business Internet Video Camera before 1.1.2.6 do not properly restrict read access to passwords, which allows context-dependent attackers to obtain sensitive information, related to (1) access by remote authenticated users to a PVC2300 or WVC2300 via a crafted URL, (2) leveraging setup privileges on a WVC200 or WVC210, and (3) leveraging administrative privileges on an RVS4000, aka Bug ID CSCte64726.

Affected products and versions

cisco pvc2300 · … → 1.1.1.4
cisco rvs4000
cisco rvs4000 · … → 1.3.1.0
cisco wvc200
cisco wvc200 · … → 1.1.0.15
cisco wvc210
cisco wvc210 · … → 1.1.0.15
cisco wvc2300 · … → 1.1.1.4

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References