CVE-2010-0593

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
22/04/2010
Last modified:
17/08/2017

Description

The Cisco RVS4000 4-port Gigabit Security Router before 1.3.2.0, PVC2300 Business Internet Video Camera before 1.1.2.6, WVC200 Wireless-G PTZ Internet Video Camera before 1.1.1.15, WVC210 Wireless-G PTZ Internet Video Camera before 1.1.1.15, and WVC2300 Wireless-G Business Internet Video Camera before 1.1.2.6 do not properly restrict read access to passwords, which allows context-dependent attackers to obtain sensitive information, related to (1) access by remote authenticated users to a PVC2300 or WVC2300 via a crafted URL, (2) leveraging setup privileges on a WVC200 or WVC210, and (3) leveraging administrative privileges on an RVS4000, aka Bug ID CSCte64726.

Vulnerable products and versions

CPE From Up to
cpe:2.3:h:cisco:pvc2300:*:*:*:*:*:*:*:* 1.1.1.4 (including)
cpe:2.3:h:cisco:wvc200:*:*:*:*:*:*:*:* 1.1.0.15 (including)
cpe:2.3:h:cisco:wvc200:1.1.0.12:*:*:*:*:*:*:*
cpe:2.3:h:cisco:wvc210:*:*:*:*:*:*:*:* 1.1.0.15 (including)
cpe:2.3:h:cisco:wvc210:1.1.0.12:*:*:*:*:*:*:*
cpe:2.3:h:cisco:wvc2300:*:*:*:*:*:*:*:* 1.1.1.4 (including)
cpe:2.3:h:cisco:rvs4000:*:*:*:*:*:*:*:* 1.3.1.0 (including)
cpe:2.3:h:cisco:rvs4000:1.3.0.5:*:*:*:*:*:*:*