CVE-2013-1601
published 2020-01-28CVE-2013-1601: An Information Disclosure vulnerability exists due to a failure to restrict access on the lums.cgi script when processing a live video stream in D-LINK An…
PriorityP344medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EXPLOIT
EPSS
12.73%
95.8th percentile
An Information Disclosure vulnerability exists due to a failure to restrict access on the lums.cgi script when processing a live video stream in D-LINK An Information Disclosure vulnerability exists due to a failure to restrict access on the lums.cgi script when processing a live video stream in D-LINK WCS-1100 1.02, TESCO DCS-2121 1.05_TESCO, TESCO DCS-2102 1.05_TESCO, DCS-7510 1.00, DCS-7410 1.00, DCS-6410 1.00, DCS-5635 1.01, DCS-5605 1.01, DCS-5230L 1.02, DCS-5230 1.02, DCS-3430 1.02, DCS-3411 1.02, DCS-3410 1.02, DCS-2121 1.06_FR, DCS-2121 1.06, DCS-2121 1.05_RU, DCS-2102 1.06_FR, DCS-2102 1.06, DCS-2102 1.05_RU, DCS-1130L 1.04, DCS-1130 1.04_US, DCS-1130 1.03, DCS-1100L 1.04, DCS-1100 1.04_US, and DCS-1100 1.03, which could let a malicious user obtain sensitive information. which could let a malicious user obtain sensitive information.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dlink | dcs-1100_firmware | — | — |
| dlink | dcs-1100_firmware | — | — |
| dlink | dcs-1100l_firmware | — | — |
| dlink | dcs-1130_firmware | — | — |
| dlink | dcs-1130_firmware | — | — |
| dlink | dcs-1130l_firmware | — | — |
| dlink | dcs-2102_firmware | — | — |
| dlink | dcs-2102_firmware | — | — |
| dlink | dcs-2121_firmware | — | — |
| dlink | dcs-2121_firmware | — | — |
| dlink | dcs-3410_firmware | — | — |
| dlink | dcs-3411_firmware | — | — |
| dlink | dcs-3430_firmware | — | — |
| dlink | dcs-5230_firmware | — | — |
| dlink | dcs-5230l_firmware | — | — |
| dlink | dcs-5605_firmware | — | — |
| dlink | dcs-5635_firmware | — | — |
| dlink | dcs-6410_firmware | — | — |
| dlink | dcs-7410_firmware | — | — |
| dlink | dcs-7510_firmware | — | — |
| dlink | wcs-1100_firmware | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
ET EXPLOIT D-Link IP Camera Vulnerable HTTP Request (CVE-2013-1601)
suricata·2014-11-25·CVSS 5.3
CVE-2013-1601 [MEDIUM] ET EXPLOIT D-Link IP Camera Vulnerable HTTP Request (CVE-2013-1601)
ET EXPLOIT D-Link IP Camera Vulnerable HTTP Request (CVE-2013-1601)
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET EXPLOIT D-Link IP Camera Vulnerable HTTP Request (CVE-2013-1601)"; flow:established,to_server; urilen:12; http.method; content:"GET"; http.uri; content:"/md/lums.cgi"; fast_pattern; reference:url,www.coresecurity.com/advisories/d-link-ip-cameras-multiple-vulnerabilities; classtype:attempted-admin; sid:2019803; rev:4; metadata:created_at 2014_11_25, cve CVE_2013_1601, signature_severity Major, updated_at 2020_09_28;)
No writeups or analysis indexed.
http://www.securityfocus.com/bid/59570https://exchange.xforce.ibmcloud.com/vulnerabilities/83939https://packetstormsecurity.com/files/cve/CVE-2013-1601https://vuldb.com/?id.8573https://www.coresecurity.com/advisories/d-link-ip-cameras-multiple-vulnerabilitieshttp://www.securityfocus.com/bid/59570https://exchange.xforce.ibmcloud.com/vulnerabilities/83939https://packetstormsecurity.com/files/cve/CVE-2013-1601https://vuldb.com/?id.8573https://www.coresecurity.com/advisories/d-link-ip-cameras-multiple-vulnerabilities
2020-01-28
Published