Brickcom FB-100Ap, WCB-100Ap, MD-100Ap, WFB-100Ap, OB-100Ae, OSD-040E, and possibly other camera models with firmware 3.0.6.16C1 and earlier, do not properly restrict access to configfile.dump, which allow remote attackers to obtain sensitive information (user names, passwords, and configurations) via a get action.
References
Configurations
Configuration 1 (hide)
AND |
|
History
04 Mar 2025, 19:48
Type | Values Removed | Values Added |
---|---|---|
First Time |
Brickcom wcb-100ap
Brickcom Brickcom wfb-100ap Brickcom fb-100ap Brickcom md-100ap Brickcom osd-040e Brickcom 100ap Device Firmware Brickcom ob-100ae |
|
CPE | cpe:2.3:h:brickom:osd-040e:-:*:*:*:*:*:*:* cpe:2.3:h:brickom:md-100ap:-:*:*:*:*:*:*:* cpe:2.3:h:brickom:wfb-100ap:-:*:*:*:*:*:*:* cpe:2.3:h:brickom:fb-100ap:-:*:*:*:*:*:*:* cpe:2.3:o:brickom:100ap_device_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:brickom:ob-100ae:-:*:*:*:*:*:*:* |
cpe:2.3:h:brickcom:md-100ap:-:*:*:*:*:*:*:* cpe:2.3:h:brickcom:osd-040e:-:*:*:*:*:*:*:* cpe:2.3:h:brickcom:fb-100ap:-:*:*:*:*:*:*:* cpe:2.3:o:brickcom:100ap_device_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:brickcom:wfb-100ap:-:*:*:*:*:*:*:* cpe:2.3:h:brickcom:wcb-100ap:-:*:*:*:*:*:*:* cpe:2.3:h:brickcom:ob-100ae:-:*:*:*:*:*:*:* |
21 Nov 2024, 01:54
Type | Values Removed | Values Added |
---|---|---|
References | () http://seclists.org/fulldisclosure/2013/Jun/84 - |
Information
Published : 2013-10-04 23:55
Updated : 2025-04-11 00:51
NVD link : CVE-2013-3689
Mitre link : CVE-2013-3689
CVE.ORG link : CVE-2013-3689
JSON object : View
Products Affected
brickcom
- 100ap_device_firmware
- fb-100ap
- md-100ap
- wfb-100ap
- wcb-100ap
- osd-040e
- ob-100ae
CWE
CWE-264
Permissions, Privileges, and Access Controls