CVE-2013-3312
Summary
| CVE | CVE-2013-3312 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-11-21 20:15:00 UTC |
| Updated | 2019-11-27 15:55:00 UTC |
| Description | Multiple cross-site request forgery (CSRF) vulnerabilities in the Loftek Nexus 543 IP Camera allow remote attackers to hijack the authentication of unspecified victims for requests that change (1) passwords or (2) firewall configuration, as demonstrated by a request to set_users.cgi. |
Risk And Classification
Problem Types: CWE-352
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Loftek | Nexus 543 | - | All | All | All |
| Hardware | Loftek | Nexus 543 | - | All | All | All |
| Operating System | Loftek | Nexus 543 Firmware | - | All | All | All |
| Operating System | Loftek | Nexus 543 Firmware | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Vulnerability: Who is Watching Your IP Camera? | The State of Security | MISC | www.tripwire.com | Exploit, Third Party Advisory |
| Loftek Nexus 543 IP Cameras - Multiple Vulnerabilities | MISC | www.exploit-db.com | Exploit, Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.