Brickcom FB-100Ap, WCB-100Ap, MD-100Ap, WFB-100Ap, OB-100Ae, OSD-040E, and possibly other camera models with firmware 3.0.6.16C1 and earlier, do not properly restrict access to configfile.dump, which allow remote attackers to obtain sensitive information (user names, passwords, and configurations) via a get action.
References
Configurations
Configuration 1 (hide)
AND |
|
History
04 Mar 2025, 19:48
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:brickom:100ap_device_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:brickom:wfb-100ap:-:*:*:*:*:*:*:* cpe:2.3:h:brickom:wcb-100ap:-:*:*:*:*:*:*:* cpe:2.3:h:brickom:osd-040e:-:*:*:*:*:*:*:* cpe:2.3:h:brickom:md-100ap:-:*:*:*:*:*:*:* cpe:2.3:h:brickom:fb-100ap:-:*:*:*:*:*:*:* |
cpe:2.3:h:brickcom:ob-100ae:-:*:*:*:*:*:*:* cpe:2.3:o:brickcom:100ap_device_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:brickcom:fb-100ap:-:*:*:*:*:*:*:* cpe:2.3:h:brickcom:md-100ap:-:*:*:*:*:*:*:* cpe:2.3:h:brickcom:wfb-100ap:-:*:*:*:*:*:*:* cpe:2.3:h:brickcom:wcb-100ap:-:*:*:*:*:*:*:* cpe:2.3:h:brickcom:osd-040e:-:*:*:*:*:*:*:* |
First Time |
Brickcom wcb-100ap
Brickcom Brickcom osd-040e Brickcom ob-100ae Brickcom fb-100ap Brickcom 100ap Device Firmware Brickcom wfb-100ap Brickcom md-100ap |
|
References | () http://seclists.org/fulldisclosure/2013/Jun/84 - |
Information
Published : 2013-10-04 23:55
Updated : 2025-03-04 19:48
NVD link : CVE-2013-3689
Mitre link : CVE-2013-3689
JSON object : View
Products Affected
brickcom
- wcb-100ap
- fb-100ap
- wfb-100ap
- osd-040e
- md-100ap
- ob-100ae
- 100ap_device_firmware
CWE
CWE-264
Permissions, Privileges, and Access Controls