CVE-2009-2046
The embedded web server on the Cisco Video Surveillance 2500 Series IP Camera with firmware before 2.1 allows remote attackers to read arbitrary files via a (1) http or (2) https request, related to the (a) SD Camera Web Server and the (b) Wireless…
Does this matter?
Lower severity and a low EPSS score (1.14%). Track it; it rarely justifies an emergency change on its own.
Description
The embedded web server on the Cisco Video Surveillance 2500 Series IP Camera with firmware before 2.1 allows remote attackers to read arbitrary files via a (1) http or (2) https request, related to the (a) SD Camera Web Server and the (b) Wireless Camera HTTP Server, aka Bug IDs CSCsu05515 and CSCsr96497.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:L/Au:S/C:C/I:N/A:N
- EPSS
- 1.14% probability · 65th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- cisco/video surveillance 2500 series ip camera
- Source
- psirt@cisco.com
References
- http://www.cisco.com/en/US/products/products_applied_mitigation_bulletin09186a0080ad1002.html
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080ad0f8f.shtmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/35478
- http://www.securitytracker.com/id?1022445
- http://www.cisco.com/en/US/products/products_applied_mitigation_bulletin09186a0080ad1002.html
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080ad0f8f.shtmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/35478
- http://www.securitytracker.com/id?1022445
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.