Vulnslist

Cisco vulnerabilities by product, model, software, and advisory.

CVE-2010-0593

The Cisco RVS4000 4-port Gigabit Security Router before 1.3.2.0, PVC2300 Business Internet Video Camera before 1.1.2.6, WVC200 Wireless-G PTZ Internet Video Camera before 1.1.1.15, WVC210 Wireless-G PTZ Internet Video Camera before 1.1.1.15, and WVC2300 Wireless-G Business Internet Video Camera before 1.1.2.6 do not properly restrict read access to passwords, which allows context-dependent attackers to obtain sensitive information, related to (1) access by remote authenticated users to a PVC2300 or WVC2300 via a crafted URL, (2) leveraging setup privileges on a WVC200 or WVC210, and (3) leveraging administrative privileges on an RVS4000, aka Bug ID CSCte64726.

SeverityHIGH
CVSS9.0
CWECWE-264
KEV
Published
Modified

Related Products

Product Advisory Evidence
Cisco WVC2300 Wireless-G Business Internet Video Camera - Audio Firmware cisco-sa-20100421-vsc Cisco OpenVuln
Cisco WVC210 Wireless-G PTZ Internet Video Camera - 2-Way Audio Firmware cisco-sa-20100421-vsc Cisco OpenVuln
Cisco WVC200 Wireless-G PTZ Internet Video Camera - Audio Firmware cisco-sa-20100421-vsc Cisco OpenVuln
Cisco RVS4000 Gigabit Security Router - VPN Firmware cisco-sa-20100421-vsc Cisco OpenVuln
Cisco PVC2300 Business Internet Video Camera - Audio/PoE Firmware cisco-sa-20100421-vsc Cisco OpenVuln