« Volver al listado

CVE-2013-3963

Estado: ModificadaMedia (6.8)—

Cross-site request forgery (CSRF) vulnerability in goform/usermanage in Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD/LL, GXV3611HD/LL, GXV3615W/P, GXV3651FHD, GXV3662HD, GXV3615WP_HD, GXV3500, and possibly other camera models allows remote attackers to hijack the authentication of unspecified victims for requests that add users.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (11)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2013-3963",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2013-10-01T19:55:09.443",
  "references": [
    {
      "url": "http://seclists.org/fulldisclosure/2013/Jun/84",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://seclists.org/fulldisclosure/2013/Jun/84",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-352"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Cross-site request forgery (CSRF) vulnerability in goform/usermanage in Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD/LL, GXV3611HD/LL, GXV3615W/P, GXV3651FHD, GXV3662HD, GXV3615WP_HD, GXV3500, and possibly other camera models allows remote attackers to hijack the authentication of unspecified victims for requests that add users."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad de CSRF en goform/usermanage en Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD/LL, GXV3611HD/LL, GXV3615W/P, GXV3651FHD, GXV3662HD, GXV3615WP_HD, GXV3500, y posiblemente otros modelos de cámara permite a atacantes remotos secuestrar la autenticación de víctimas sin especificar para peticiones que incluyan usuarios."
    }
  ],
  "lastModified": "2026-06-16T23:56:06.167",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:grandstream:gxv_device_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "53F7233B-3C46-47AA-8FD2-5972F04C15AF",
              "versionEndIncluding": "1.0.4.43"
            },
            {
              "criteria": "cpe:2.3:o:grandstream:gxv_device_firmware:1.0.2.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "612208E1-B2B0-4E4F-921A-4368F805515E"
            },
            {
              "criteria": "cpe:2.3:o:grandstream:gxv_device_firmware:1.0.3.9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "86535E57-635F-4AD8-AE00-FD5D00E3684A"
            },
            {
              "criteria": "cpe:2.3:o:grandstream:gxv_device_firmware:1.0.4.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "90713ED3-8DD4-488C-A901-47D636A7A21E"
            },
            {
              "criteria": "cpe:2.3:o:grandstream:gxv_device_firmware:1.0.4.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "21CC85FD-7293-4187-910F-9E010841EBB0"
            },
            {
              "criteria": "cpe:2.3:o:grandstream:gxv_device_firmware:1.0.4.11:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7EEF0F10-D63E-4931-882C-CBA6BBE33F42"
            },
            {
              "criteria": "cpe:2.3:o:grandstream:gxv_device_firmware:1.0.4.16:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D02E4C11-DD10-4F22-B5E7-0A490D9D4760"
            },
            {
              "criteria": "cpe:2.3:o:grandstream:gxv_device_firmware:1.0.4.27:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1338E5F7-4EE3-4244-8E1F-2ABA50054DC7"
            },
            {
              "criteria": "cpe:2.3:o:grandstream:gxv_device_firmware:1.0.4.34:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A9D7074F-CC2B-4EED-98EA-4C895EC5EA9B"
            },
            {
              "criteria": "cpe:2.3:o:grandstream:gxv_device_firmware:1.0.4.37:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FA71D8D0-6A8E-475A-9E0E-845CBA2B7D4D"
            },
            {
              "criteria": "cpe:2.3:o:grandstream:gxv_device_firmware:1.0.4.38:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BD4DC610-777B-4F3B-8B92-5D7771CD8BBC"
            },
            {
              "criteria": "cpe:2.3:o:grandstream:gxv_device_firmware:1.0.4.39:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F76307FE-851E-44CE-9248-5F5CE7ECB2F8"
            },
            {
              "criteria": "cpe:2.3:o:grandstream:gxv_device_firmware:1.0.4.42:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E9D58580-E3E1-485C-A560-93E77F3F196C"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:grandstream:gxv3500:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EEAEBA7D-656D-4520-94CE-370A5712A380"
            },
            {
              "criteria": "cpe:2.3:h:grandstream:gxv3501:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1550A087-E35E-44EE-A19F-C69EB173E49B"
            },
            {
              "criteria": "cpe:2.3:h:grandstream:gxv3504:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "83A4BA5B-1996-4527-960C-492FD9400003"
            },
            {
              "criteria": "cpe:2.3:h:grandstream:gxv3601:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EF5CAAD0-A565-4B3A-B022-BD0130914383"
            },
            {
              "criteria": "cpe:2.3:h:grandstream:gxv3601hd\\/ll:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "73DB8462-2203-41F2-8C31-FD074240DC3C"
            },
            {
              "criteria": "cpe:2.3:h:grandstream:gxv3611hd\\/ll:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C4C4FE33-DBB7-44A9-BFC4-11A47667533C"
            },
            {
              "criteria": "cpe:2.3:h:grandstream:gxv3615w\\/p:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1B3ECC3C-43BD-4ABC-B2D7-45982BE4B929"
            },
            {
              "criteria": "cpe:2.3:h:grandstream:gxv3615wp_hd:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C79390F8-EC97-4922-81C9-184B630E8AB6"
            },
            {
              "criteria": "cpe:2.3:h:grandstream:gxv3651fhd:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "00BE6AEB-930F-471F-9DF8-1B8148557ACA"
            },
            {
              "criteria": "cpe:2.3:h:grandstream:gxv3662hd:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "36362F8F-92D6-4475-AADB-6D02971E1025"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}