SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2013-1601

An Information Disclosure vulnerability exists due to a failure to restrict access on the lums.cgi script when processing a live video stream in D-LINK An Information Disclosure vulnerability exists due to a failure to restrict access on the lums.cgi…

MEDIUM 5.3EPSS 12.7%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 12.7%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.

Description

An Information Disclosure vulnerability exists due to a failure to restrict access on the lums.cgi script when processing a live video stream in D-LINK An Information Disclosure vulnerability exists due to a failure to restrict access on the lums.cgi script when processing a live video stream in D-LINK WCS-1100 1.02, TESCO DCS-2121 1.05_TESCO, TESCO DCS-2102 1.05_TESCO, DCS-7510 1.00, DCS-7410 1.00, DCS-6410 1.00, DCS-5635 1.01, DCS-5605 1.01, DCS-5230L 1.02, DCS-5230 1.02, DCS-3430 1.02, DCS-3411 1.02, DCS-3410 1.02, DCS-2121 1.06_FR, DCS-2121 1.06, DCS-2121 1.05_RU, DCS-2102 1.06_FR, DCS-2102 1.06, DCS-2102 1.05_RU, DCS-1130L 1.04, DCS-1130 1.04_US, DCS-1130 1.03, DCS-1100L 1.04, DCS-1100 1.04_US, and DCS-1100 1.03, which could let a malicious user obtain sensitive information. which could let a malicious user obtain sensitive information.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
12.73% probability · 96th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
dlink/dcs-3411 firmware · dlink/dcs-3430 firmware · dlink/dcs-5605 firmware · dlink/dcs-5635 firmware · dlink/dcs-1100l firmware · dlink/dcs-1130l firmware · dlink/dcs-1100 firmware · dlink/dcs-1130 firmware · dlink/dcs-2102 firmware · dlink/dcs-2121 firmware · dlink/dcs-3410 firmware · dlink/dcs-5230 firmware · dlink/dcs-5230l firmware · dlink/dcs-6410 firmware · dlink/dcs-7410 firmware · dlink/dcs-7510 firmware · dlink/wcs-1100 firmware
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.