Vulnerabilities > CVE-2013-3585 - Credentials Management vulnerability in Samsung Smart Viewer

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
samsung
CWE-255
exploit available

Summary

Samsung Web Viewer for Samsung DVR devices stores credentials in cleartext, which allows context-dependent attackers to obtain sensitive information via vectors involving (1) direct access to a file or (2) the user-setup web page.

Vulnerable Configurations

Part Description Count
Application
Samsung
1
Hardware
Samsung
1

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionSamsung DVR Firmware 1.10 - Authentication Bypass. CVE-2013-3585,CVE-2013-3586. Webapps exploit for hardware platform
idEDB-ID:27753
last seen2016-02-03
modified2013-08-21
published2013-08-21
reporterAndrea Fabrizi
sourcehttps://www.exploit-db.com/download/27753/
titleSamsung DVR Firmware 1.10 - Authentication Bypass