CVE-2013-3542
CRITICAL
10,0
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: changed
Confidentiality: high
Integrity: high
Availability: high
HIGH
10,0
Source: [email protected]
Access Vector: network
Access Complexity: low
Authentication: none
Confidentiality: complete
Integrity: complete
Availability: complete
Description
AI Translation Available
Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD/LL, GXV3611HD/LL, GXV3615W/P, GXV3651FHD, GXV3662HD, GXV3615WP_HD, GXV3500, and possibly other camera models with firmware 1.0.4.11, have a hardcoded account '!#/' with the same password, which makes it easier for remote attackers to obtain access via a TELNET session.
EPSS (Exploit Prediction Scoring System)
Trend Analysis
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score
0,0324
Percentile
0,9th
Updated
EPSS Score Trend (Last 90 Days)
798
Use of Hard-coded Credentials
DraftCommon Consequences
Security Scopes Affected:
Access Control
Integrity
Confidentiality
Availability
Other
Potential Impacts:
Bypass Protection Mechanism
Read Application Data
Gain Privileges Or Assume Identity
Execute Unauthorized Code Or Commands
Other
Applicable Platforms
Technologies:
Mobile, ICS/OT
Operating System
Gxv3501 Firmware by Grandstream
CPE Identifier
View Detailed Analysis
cpe:2.3:o:grandstream:gxv3501_firmware:1.0.4.11:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Gxv3601Ll Firmware by Grandstream
CPE Identifier
View Detailed Analysis
cpe:2.3:o:grandstream:gxv3601ll_firmware:1.0.4.11:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Gxv3601 Firmware by Grandstream
CPE Identifier
View Detailed Analysis
cpe:2.3:o:grandstream:gxv3601_firmware:1.0.4.11:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Gxv3500 Firmware by Grandstream
CPE Identifier
View Detailed Analysis
cpe:2.3:o:grandstream:gxv3500_firmware:1.0.4.11:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Gxv3611Hd Firmware by Grandstream
CPE Identifier
View Detailed Analysis
cpe:2.3:o:grandstream:gxv3611hd_firmware:1.0.4.11:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Gxv3615W Firmware by Grandstream
CPE Identifier
View Detailed Analysis
cpe:2.3:o:grandstream:gxv3615w_firmware:1.0.4.11:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Gxv3615P Firmware by Grandstream
CPE Identifier
View Detailed Analysis
cpe:2.3:o:grandstream:gxv3615p_firmware:1.0.4.11:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Gxv3615Wp Hd Firmware by Grandstream
CPE Identifier
View Detailed Analysis
cpe:2.3:o:grandstream:gxv3615wp_hd_firmware:1.0.4.11:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Gxv3611Ll Firmware by Grandstream
CPE Identifier
View Detailed Analysis
cpe:2.3:o:grandstream:gxv3611ll_firmware:1.0.4.11:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Gxv3662Hd Firmware by Grandstream
CPE Identifier
View Detailed Analysis
cpe:2.3:o:grandstream:gxv3662hd_firmware:1.0.4.11:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Gxv3651Fhd Firmware by Grandstream
CPE Identifier
View Detailed Analysis
cpe:2.3:o:grandstream:gxv3651fhd_firmware:1.0.4.11:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Gxv3504 Firmware by Grandstream
CPE Identifier
View Detailed Analysis
cpe:2.3:o:grandstream:gxv3504_firmware:1.0.4.11:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Gxv3601Hd Firmware by Grandstream
CPE Identifier
View Detailed Analysis
cpe:2.3:o:grandstream:gxv3601hd_firmware:1.0.4.11:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
http://seclists.org/fulldisclosure/2013/Jun/84
https://www.youtube.com/watch?v=XkCBs4lenhI
http://seclists.org/fulldisclosure/2013/Jun/84
https://www.youtube.com/watch?v=XkCBs4lenhI