Overview
Samsung Web Viewer for Samsung DVR contains multiple vulnerabilities including: Cleartext Storage in a File or on Disk (CWE-313) and Authentication Bypass by Assumed-Immutable Data (CWE-302).
Description
CWE-313: Cleartext Storage in a File or on Disk - CVE-2013-3585 Web Viewer for Samsung DVR stores user credentials in plaintext allowing an attacker to parse saved credentials on the user setup webpage. |
Impact
A remote unauthenticated attacker may be able to retrieve the device's administrator password, allowing them to directly access the device's configuration web page or system password configuration files. |
Solution
Apply an Update |
Restrict access to the Samsung Web Viewer for Samsung DVR interface |
Vendor Information
CVSS Metrics
| Group | Score | Vector |
|---|---|---|
| Base | 7.6 | AV:N/AC:H/Au:N/C:C/I:C/A:C |
| Temporal | 5.4 | E:POC/RL:OF/RC:UC |
| Environmental | 4.1 | CDP:N/TD:M/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
Thanks to Andrey Bezborodov for reporting this vulnerability.
This document was written by Adam Rauf.
Other Information
| CVE IDs: | CVE-2013-3585, CVE-2013-3586 |
| Date Public: | 2013-08-21 |
| Date First Published: | 2013-08-21 |
| Date Last Updated: | 2013-10-03 19:14 UTC |
| Document Revision: | 35 |