Overview
Samsung Web Viewer for Samsung DVR contains multiple vulnerabilities including: Cleartext Storage in a File or on Disk (CWE-313) and Authentication Bypass by Assumed-Immutable Data (CWE-302).
Description
CWE-313: Cleartext Storage in a File or on Disk - CVE-2013-3585 Web Viewer for Samsung DVR stores user credentials in plaintext allowing an attacker to parse saved credentials on the user setup webpage. |
Impact
A remote unauthenticated attacker may be able to retrieve the device's administrator password, allowing them to directly access the device's configuration web page or system password configuration files. |
Solution
Apply an Update |
Restrict access to the Samsung Web Viewer for Samsung DVR interface |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 7.6 | AV:N/AC:H/Au:N/C:C/I:C/A:C |
Temporal | 5.4 | E:POC/RL:OF/RC:UC |
Environmental | 4.1 | CDP:N/TD:M/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
Thanks to Andrey Bezborodov for reporting this vulnerability.
This document was written by Adam Rauf.
Other Information
CVE IDs: | CVE-2013-3585, CVE-2013-3586 |
Date Public: | 2013-08-21 |
Date First Published: | 2013-08-21 |
Date Last Updated: | 2013-10-03 19:14 UTC |
Document Revision: | 35 |