« Volver al listado

CVE-2013-5535

Estado: ModificadaMedia (6.4)—

The analytics page on Cisco Video Surveillance 4000 IP cameras has hardcoded credentials, which allows remote attackers to watch the video feed by leveraging knowledge of the password, aka Bug IDs CSCuj70402 and CSCuj70419.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2013-5535",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@cisco.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2013-10-16T10:52:45.307",
  "references": [
    {
      "url": "http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-5535",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@cisco.com"
    },
    {
      "url": "http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-5535",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-255"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The analytics page on Cisco Video Surveillance 4000 IP cameras has hardcoded credentials, which allows remote attackers to watch the video feed by leveraging knowledge of the password, aka Bug IDs CSCuj70402 and CSCuj70419."
    },
    {
      "lang": "es",
      "value": "La página de analíticas en cámaras IP Cisco Video Surveillance 4000 tiene credenciales embebidas en el código, lo que permite a atacantes remotos ver el streaming de video aprovechando el conocimiento de la contraseña, tambien conocido como Bug ID SCuj70402 y CSCuj70419."
    }
  ],
  "lastModified": "2026-06-16T23:58:58.533",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:cisco:video_surveillance_4000_ip_camera:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7725752F-91EE-4BDA-83A7-3830ED6D0791"
            },
            {
              "criteria": "cpe:2.3:h:cisco:video_surveillance_4300e_ip_camera:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ABE86502-7BBF-43C5-BFF2-0BF4E2D3C0C6"
            },
            {
              "criteria": "cpe:2.3:h:cisco:video_surveillance_4500e_ip_camera:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A0F88241-1468-4C3C-A4AF-513B7FAE85B0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@cisco.com"
}