VulnerabilityModified
CVE-2013-3586
Samsung Web Viewer for Samsung DVR devices allows remote attackers to bypass authentication via an arbitrary SessionID value in a cookie.
HIGH 7.6EPSS 11.2%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 11.2%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Samsung Web Viewer for Samsung DVR devices allows remote attackers to bypass authentication via an arbitrary SessionID value in a cookie.
- CVSS 2.0
- 7.6 HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
- EPSS
- 11.15% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- samsung/smart viewer · samsung/dvr
- Source
- cret@cert.org
References
- http://www.kb.cert.org/vuls/id/882286US Government Resource
- http://www.kb.cert.org/vuls/id/882286US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.