ID

VAR-201004-0154


CVE

CVE-2010-0593


TITLE

Cisco RVS4000 4-port Gigabit Security Router Vulnerabilities that collect important information

Trust: 0.8

sources: JVNDB: JVNDB-2010-003836

DESCRIPTION

The Cisco RVS4000 4-port Gigabit Security Router before 1.3.2.0, PVC2300 Business Internet Video Camera before 1.1.2.6, WVC200 Wireless-G PTZ Internet Video Camera before 1.1.1.15, WVC210 Wireless-G PTZ Internet Video Camera before 1.1.1.15, and WVC2300 Wireless-G Business Internet Video Camera before 1.1.2.6 do not properly restrict read access to passwords, which allows context-dependent attackers to obtain sensitive information, related to (1) access by remote authenticated users to a PVC2300 or WVC2300 via a crafted URL, (2) leveraging setup privileges on a WVC200 or WVC210, and (3) leveraging administrative privileges on an RVS4000, aka Bug ID CSCte64726. Multiple Cisco Small Business Video Surveillance cameras and a 4-port Gigabit router are prone to a remote authentication-bypass vulnerability. Successful exploits allow remote authenticated attackers to obtain other users' passwords and gain access to the vulnerable device. This will completely compromise an affected device. This issue is being tracked by Cisco bug ID CSCte64726. The vulnerability exists in the handling of requests to the web-based management interface, which can be exploited to view the device's configuration data (e.g. Successful exploitation requires "setup" privileges on the WVC200 and WVC210 models and administrative privileges on the RVS4000 model. PROVIDED AND/OR DISCOVERED BY: Reported by the vendor. ORIGINAL ADVISORY: http://www.cisco.com/warp/public/707/cisco-sa-20100421-vsc.shtml ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help private users keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/advisories/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/advisories/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. Cisco has released free software updates that address this vulnerability. Workarounds that mitigate this vulnerability are available on some devices. This advisory is posted at: http://www.cisco.com/warp/public/707/cisco-sa-20100421-vsc.shtml. No other Cisco cameras or products are currently known to be affected by this vulnerability. An administrator can restrict a user's ability to manage the device, allowing the user to employ the camera for surveillance only. The Cisco RVS4000 Gigabit Security Router delivers high-speed network access and IPsec VPN capabilities for as many as five users. The Cisco RVS4000 also provides firewall and intrusion prevention capabilities. The user could then view the passwords for all users on the device. A user on the WVC200 and WVC210 camera must have been granted setup privileges to take advantage of this vulnerability to view the passwords. The ability to configure setup privileges is not available on the other devices affected by this vulnerability. Administrative users on the RVS4000 router may be able to view the passwords of other administrative users. Vulnerability Scoring Details +---------------------------- Cisco has provided scores for the vulnerability in this advisory based on the Common Vulnerability Scoring System (CVSS). The CVSS scoring in this Security Advisory is done in accordance with CVSS version 2.0. CVSS is a standards-based scoring method that conveys vulnerability severity and helps determine urgency and priority of response. Cisco has provided a base and temporal score. Customers can then compute environmental scores to assist in determining the impact of the vulnerability in individual networks. Cisco has provided an FAQ to answer additional questions regarding CVSS at: http://www.cisco.com/web/about/security/intelligence/cvss-qandas.html Cisco has also provided a CVSS calculator to help compute the environmental impact for individual networks at: http://intellishield.cisco.com/security/alertmanager/cvss * CSCte64726 ("Unprivileged users may be able to view passwords for other users") CVSS Base Score - 9.0 Access Vector - Network Access Complexity - Low Authentication - Single Confidentiality Impact - Complete Integrity Impact - Complete Availability Impact - Complete CVSS Temporal Score - 7.4 Exploitability - Functional Remediation Level - Official-Fix Report Confidence - Confirmed Impact ====== Successful exploitation of the vulnerability could allow an authenticated user to discover all the user passwords contained on the device. Software Versions and Fixes =========================== To determine the software version running on a camera, administrators can click the "About" tab at the top-right of the device user interface. The software version information can be obtained on the System Status page under the "Status" tab. The latest camera software can be downloaded at: http://tools.cisco.com/support/downloads/go/Redirect.x?mdfid=282414029 The software version of the RVS4000 is displayed on the main router page displayed after users log in. The latest RVS4000 software can be downloaded at: http://tools.cisco.com/support/downloads/pub/Redirect.x?mdfid=282413304 When considering software upgrades, also consult http://www.cisco.com/go/psirt and any subsequent advisories to determine exposure and a complete upgrade solution. In all cases, customers should exercise caution to be certain the devices to be upgraded contain sufficient memory and that current hardware and software configurations will continue to be supported properly by the new release. If the information is not clear, contact the Cisco Small Business Support Center or your contracted maintenance provider for assistance. +---------------------------------------+ | Product | First Fixed Version | |-----------+---------------------------| | PVC2300 | 1.1.2.6 | |-----------+---------------------------| | WVC200 | 1.1.1.15 | |-----------+---------------------------| | WVC210 | 1.1.1.15 | |-----------+---------------------------| | WVC2300 | 1.1.2.6 | |-----------+---------------------------| | RVS4000 | 1.3.2.0 | +---------------------------------------+ Workarounds =========== There are no workarounds for the RVS4000, PVC2300, and WVC2300 cameras. On the WVC200 and WVC210 cameras, make sure that only trusted users are given setup privileges. Obtaining Fixed Software ======================== Cisco has released free software updates that address this vulnerability. Prior to deploying software, customers should check the software for feature set compatibility and known issues specific to their environment. Customers may only install and expect support for the feature sets they have purchased. By installing, downloading, accessing or otherwise using such software upgrades, customers agree to be bound by the terms of Cisco's software license terms found at http://www.cisco.com/en/US/docs/general/warranty/English/EU1KEN_.html, or as otherwise set forth at Cisco.com Downloads at http://www.cisco.com/public/sw-center/sw-usingswc.shtml. Do not contact psirt@cisco.com or security-alert@cisco.com for software upgrades. Customers should obtain upgraded software through their regular update channels. For most customers, this means that upgrades should be obtained through the Software Center on Cisco's worldwide website at http://www.cisco.com. If the information is not clear, please contact the Cisco Small Business Support Center or your contracted maintenance provider for assistance. Small Business Support Center contacts are as follows. * +1 866 606 1866 (toll free from within North America) * +1 408 418 1866 (toll call from anywhere in the world) Customers should have their product serial number available. Refer to http://www.cisco.com/en/US/support/tsd_cisco_small_business_support_center_contacts.html for additional support contact information, including localized telephone numbers, and instructions and e-mail addresses for use in various languages. Exploitation and Public Announcements ===================================== The Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerability described in this advisory. Status of this Notice: FINAL ============================ THIS DOCUMENT IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. CISCO RESERVES THE RIGHT TO CHANGE OR UPDATE THIS DOCUMENT AT ANY TIME. A stand-alone copy or Paraphrase of the text of this document that omits the distribution URL in the following section is an uncontrolled copy, and may lack important information or contain factual errors. Distribution ============ This advisory is posted on Cisco's worldwide website at: http://www.cisco.com/warp/public/707/cisco-sa-20100421-vsc.shtml In addition to worldwide web posting, a text version of this notice is clear-signed with the Cisco PSIRT PGP key and is posted to the following e-mail and Usenet news recipients. * cust-security-announce@cisco.com * first-bulletins@lists.first.org * bugtraq@securityfocus.com * vulnwatch@vulnwatch.org * cisco@spot.colorado.edu * cisco-nsp@puck.nether.net * full-disclosure@lists.grok.org.uk * comp.dcom.sys.cisco@newsgate.cisco.com Future updates of this advisory, if any, will be placed on Cisco's worldwide website, but may or may not be actively announced on mailing lists or newsgroups. Users concerned about this problem are encouraged to check the above URL for any updates. Revision History ================ +------------------------------------------------------------+ | Revision 1.0 | 2010-April-21 | Initial public release. | +------------------------------------------------------------+ Cisco Security Procedures ========================= Complete information on reporting security vulnerabilities in Cisco products, obtaining assistance with security incidents, and registering to receive security information from Cisco, is available on Cisco's worldwide website at http://www.cisco.com/en/US/products/products_security_vulnerability_policy.html. This includes instructions for press inquiries regarding Cisco security notices. All Cisco security advisories are available at http://www.cisco.com/go/psirt. +-------------------------------------------------------------------- Copyright 2008-2010 Cisco Systems, Inc. All rights reserved. +-------------------------------------------------------------------- Updated: Apr 21, 2010 Document ID: 111641 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iEYEARECAAYFAkvPGXQACgkQ86n/Gc8U/uBKuQCgiymrWHvk3jBZONrLFlCcKVkM 0NAAnRcF8F+XYWyzMcQup+/35mxOsmhL =xpSH -----END PGP SIGNATURE-----

Trust: 2.16

sources: NVD: CVE-2010-0593 // JVNDB: JVNDB-2010-003836 // BID: 39612 // VULHUB: VHN-43198 // PACKETSTORM: 88801 // PACKETSTORM: 88778

AFFECTED PRODUCTS

vendor:ciscomodel:rvs4000scope:eqversion:1.3.0.5

Trust: 1.6

vendor:ciscomodel:wvc200scope:eqversion:1.1.0.12

Trust: 1.6

vendor:ciscomodel:wvc210scope:eqversion:1.1.0.12

Trust: 1.6

vendor:ciscomodel:wvc210scope:lteversion:1.1.0.15

Trust: 1.0

vendor:ciscomodel:rvs4000scope:lteversion:1.3.1.0

Trust: 1.0

vendor:ciscomodel:wvc200scope:lteversion:1.1.0.15

Trust: 1.0

vendor:ciscomodel:wvc2300scope:lteversion:1.1.1.4

Trust: 1.0

vendor:ciscomodel:pvc2300scope:lteversion:1.1.1.4

Trust: 1.0

vendor:ciscomodel:pvc2300 business internet video camerascope:ltversion:1.1.2.6

Trust: 0.8

vendor:ciscomodel:rvs4000 4-port gigabit security routerscope:ltversion:1.3.2.0

Trust: 0.8

vendor:ciscomodel:wvc200 wireless-g ptz internet video camerascope:ltversion:1.1.1.15

Trust: 0.8

vendor:ciscomodel:wvc210 wireless-g ptz internet video camerascope:ltversion:1.1.1.15

Trust: 0.8

vendor:ciscomodel:wvc2300 wireless-g business internet video camerascope:ltversion:1.1.2.6

Trust: 0.8

vendor:ciscomodel:wvc2300scope:eqversion:1.1.1.4

Trust: 0.6

vendor:ciscomodel:wvc210scope:eqversion:1.1.0.15

Trust: 0.6

vendor:ciscomodel:pvc2300scope:eqversion:1.1.1.4

Trust: 0.6

vendor:ciscomodel:rvs4000scope:eqversion:1.3.1.0

Trust: 0.6

vendor:ciscomodel:wvc200scope:eqversion:1.1.0.15

Trust: 0.6

vendor:ciscomodel:wireless-g ptz internet video camera wvc210scope:eqversion:0

Trust: 0.3

vendor:ciscomodel:wireless-g ptz internet video camera wvc200scope:eqversion:1.1.1.15

Trust: 0.3

vendor:ciscomodel:wireless-g ptz internet video camera wvc200scope:eqversion:0

Trust: 0.3

vendor:ciscomodel:wireless-g business internet video camera wvc2300scope:eqversion:0

Trust: 0.3

vendor:ciscomodel:rvs4000 4-port gigabit security routerscope:eqversion:0

Trust: 0.3

vendor:ciscomodel:business internet video camera pvc2300scope:eqversion:0

Trust: 0.3

vendor:ciscomodel:wireless-g ptz internet video camera wvc210scope:neversion:1.1.15

Trust: 0.3

vendor:ciscomodel:wireless-g ptz internet video camera wvc200scope:neversion:1.2.2.0

Trust: 0.3

vendor:ciscomodel:wireless-g business internet video camera wvc2300scope:neversion:1.1.2.6

Trust: 0.3

vendor:ciscomodel:rvs4000 4-port gigabit security routerscope:neversion:1.3.2.0

Trust: 0.3

vendor:ciscomodel:business internet video camera pvc2300scope:neversion:1.1.2.6

Trust: 0.3

sources: BID: 39612 // JVNDB: JVNDB-2010-003836 // CNNVD: CNNVD-201004-376 // NVD: CVE-2010-0593

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2010-0593
value: HIGH

Trust: 1.0

NVD: CVE-2010-0593
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201004-376
value: CRITICAL

Trust: 0.6

VULHUB: VHN-43198
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2010-0593
severity: HIGH
baseScore: 9.0
vectorString: AV:N/AC:L/AU:S/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-43198
severity: HIGH
baseScore: 9.0
vectorString: AV:N/AC:L/AU:S/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-43198 // JVNDB: JVNDB-2010-003836 // CNNVD: CNNVD-201004-376 // NVD: CVE-2010-0593

PROBLEMTYPE DATA

problemtype:CWE-264

Trust: 1.9

sources: VULHUB: VHN-43198 // JVNDB: JVNDB-2010-003836 // NVD: CVE-2010-0593

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201004-376

TYPE

permissions and access control

Trust: 0.6

sources: CNNVD: CNNVD-201004-376

CONFIGURATIONS

sources: JVNDB: JVNDB-2010-003836

EXPLOIT AVAILABILITY

sources: VULHUB: VHN-43198

PATCH

title:cisco-sa-20100421-vscurl:http://www.cisco.com/en/US/products/csa/cisco-sa-20100421-vsc.html

Trust: 0.8

sources: JVNDB: JVNDB-2010-003836

EXTERNAL IDS

db:NVDid:CVE-2010-0593

Trust: 2.9

db:BIDid:39612

Trust: 1.4

db:SECUNIAid:39510

Trust: 1.2

db:OSVDBid:63978

Trust: 1.1

db:SECTRACKid:1023906

Trust: 1.1

db:VUPENid:ADV-2010-0965

Trust: 1.1

db:JVNDBid:JVNDB-2010-003836

Trust: 0.8

db:CNNVDid:CNNVD-201004-376

Trust: 0.7

db:CISCOid:20100421 CISCO SMALL BUSINESS VIDEO SURVEILLANCE CAMERAS AND CISCO 4-PORT GIGABIT SECURITY ROUTERS AUTHENTICATION BYPASS VULNERABILITY

Trust: 0.6

db:PACKETSTORMid:88778

Trust: 0.2

db:VULHUBid:VHN-43198

Trust: 0.1

db:PACKETSTORMid:88801

Trust: 0.1

sources: VULHUB: VHN-43198 // BID: 39612 // JVNDB: JVNDB-2010-003836 // PACKETSTORM: 88801 // PACKETSTORM: 88778 // CNNVD: CNNVD-201004-376 // NVD: CVE-2010-0593

REFERENCES

url:http://www.cisco.com/en/us/products/products_security_advisory09186a0080b27511.shtml

Trust: 1.7

url:http://www.securityfocus.com/bid/39612

Trust: 1.1

url:http://osvdb.org/63978

Trust: 1.1

url:http://www.securitytracker.com/id?1023906

Trust: 1.1

url:http://secunia.com/advisories/39510

Trust: 1.1

url:http://www.vupen.com/english/advisories/2010/0965

Trust: 1.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/58034

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2010-0593

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2010-0593

Trust: 0.8

url:http://www.cisco.com

Trust: 0.3

url:/archive/1/510867

Trust: 0.3

url:http://www.cisco.com/warp/public/707/cisco-sa-20100421-vsc.shtml#@id

Trust: 0.3

url:http://www.cisco.com/warp/public/707/cisco-sa-20100421-vsc.shtml

Trust: 0.2

url:http://secunia.com/advisories/secunia_security_advisories/

Trust: 0.1

url:http://secunia.com/advisories/39510/

Trust: 0.1

url:http://secunia.com/vulnerability_scanning/corporate/wsus_sccm_3rd_third_party_patching/

Trust: 0.1

url:http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org

Trust: 0.1

url:http://secunia.com/advisories/about_secunia_advisories/

Trust: 0.1

url:http://www.cisco.com/en/us/products/products_security_vulnerability_policy.html.

Trust: 0.1

url:http://www.cisco.com/go/psirt

Trust: 0.1

url:http://tools.cisco.com/support/downloads/go/redirect.x?mdfid=282414029

Trust: 0.1

url:http://www.cisco.com/en/us/support/tsd_cisco_small_business_support_center_contacts.html

Trust: 0.1

url:http://www.cisco.com/warp/public/707/cisco-sa-20100421-vsc.shtml.

Trust: 0.1

url:http://www.cisco.com/web/about/security/intelligence/cvss-qandas.html

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-0593

Trust: 0.1

url:http://www.cisco.com.

Trust: 0.1

url:http://www.cisco.com/en/us/products/ps9928/index.html

Trust: 0.1

url:http://www.cisco.com/go/psirt.

Trust: 0.1

url:http://www.cisco.com/public/sw-center/sw-usingswc.shtml.

Trust: 0.1

url:http://tools.cisco.com/support/downloads/pub/redirect.x?mdfid=282413304

Trust: 0.1

url:http://www.cisco.com/en/us/docs/general/warranty/english/eu1ken_.html,

Trust: 0.1

url:http://www.cisco.com/cisco/web/solutions/small_business/products/security/small_business_video_surveillance_cameras/index.html

Trust: 0.1

url:http://intellishield.cisco.com/security/alertmanager/cvss

Trust: 0.1

sources: VULHUB: VHN-43198 // BID: 39612 // JVNDB: JVNDB-2010-003836 // PACKETSTORM: 88801 // PACKETSTORM: 88778 // CNNVD: CNNVD-201004-376 // NVD: CVE-2010-0593

CREDITS

Eljakim Schrijvers of Eljakim Information Technology bv

Trust: 0.3

sources: BID: 39612

SOURCES

db:VULHUBid:VHN-43198
db:BIDid:39612
db:JVNDBid:JVNDB-2010-003836
db:PACKETSTORMid:88801
db:PACKETSTORMid:88778
db:CNNVDid:CNNVD-201004-376
db:NVDid:CVE-2010-0593

LAST UPDATE DATE

2024-11-23T22:53:41.380000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-43198date:2017-08-17T00:00:00
db:BIDid:39612date:2010-05-17T18:12:00
db:JVNDBid:JVNDB-2010-003836date:2012-06-26T00:00:00
db:CNNVDid:CNNVD-201004-376date:2010-04-22T00:00:00
db:NVDid:CVE-2010-0593date:2024-11-21T01:12:32.250

SOURCES RELEASE DATE

db:VULHUBid:VHN-43198date:2010-04-22T00:00:00
db:BIDid:39612date:2010-04-21T00:00:00
db:JVNDBid:JVNDB-2010-003836date:2012-06-26T00:00:00
db:PACKETSTORMid:88801date:2010-04-22T06:51:24
db:PACKETSTORMid:88778date:2010-04-22T01:45:02
db:CNNVDid:CNNVD-201004-376date:2010-04-22T00:00:00
db:NVDid:CVE-2010-0593date:2010-04-22T14:30:00.853