Cross-site request forgery (CSRF) vulnerability in cgi-bin/users.cgi in Brickcom FB-100Ap, WCB-100Ap, MD-100Ap, WFB-100Ap, OB-100Ae, OSD-040E, and possibly other camera models with firmware 3.1.0.8 and earlier, allows remote attackers to hijack the authentication of administrators for requests that add users.
Subscriptions
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2013-3623 | Cross-site request forgery (CSRF) vulnerability in cgi-bin/users.cgi in Brickcom FB-100Ap, WCB-100Ap, MD-100Ap, WFB-100Ap, OB-100Ae, OSD-040E, and possibly other camera models with firmware 3.1.0.8 and earlier, allows remote attackers to hijack the authentication of administrators for requests that add users. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| http://seclists.org/fulldisclosure/2013/Jun/84 |
|
History
Tue, 04 Mar 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Brickcom
Brickcom 100ap Device Firmware Brickcom fb-100ap Brickcom md-100ap Brickcom ob-100ae Brickcom osd-040e Brickcom wcb-100ap Brickcom wfb-100ap |
|
| CPEs | cpe:2.3:h:brickom:md-100ap:-:*:*:*:*:*:*:* cpe:2.3:h:brickom:ob-100ae:-:*:*:*:*:*:*:* cpe:2.3:h:brickom:osd-040e:-:*:*:*:*:*:*:* cpe:2.3:h:brickom:wcb-100ap:-:*:*:*:*:*:*:* cpe:2.3:h:brickom:wfb-100ap:-:*:*:*:*:*:*:* cpe:2.3:o:brickom:100ap_device_firmware:3.1.0.8:*:*:*:*:*:*:* |
cpe:2.3:h:brickcom:fb-100ap:-:*:*:*:*:*:*:* cpe:2.3:h:brickcom:md-100ap:-:*:*:*:*:*:*:* cpe:2.3:h:brickcom:ob-100ae:-:*:*:*:*:*:*:* cpe:2.3:h:brickcom:osd-040e:-:*:*:*:*:*:*:* cpe:2.3:h:brickcom:wcb-100ap:-:*:*:*:*:*:*:* cpe:2.3:h:brickcom:wfb-100ap:-:*:*:*:*:*:*:* cpe:2.3:o:brickcom:100ap_device_firmware:3.1.0.8:*:*:*:*:*:*:* |
| Vendors & Products |
Brickom
Brickom 100ap Device Firmware Brickom fb-100ap Brickom md-100ap Brickom ob-100ae Brickom osd-040e Brickom wcb-100ap Brickom wfb-100ap |
Brickcom
Brickcom 100ap Device Firmware Brickcom fb-100ap Brickcom md-100ap Brickcom ob-100ae Brickcom osd-040e Brickcom wcb-100ap Brickcom wfb-100ap |
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-17T04:28:59.577Z
Reserved: 2013-05-29T00:00:00.000Z
Link: CVE-2013-3690
No data.
Status : Deferred
Published: 2013-10-01T19:55:09.397
Modified: 2025-04-11T00:51:21.963
Link: CVE-2013-3690
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD