CVE-2013-5006
Published Jul 31, 2013
Last updated 5 years ago
Overview
- Description
- main_internet.php on the Western Digital My Net N600 and N750 with firmware 1.03.12 and 1.04.16, and the N900 and N900C with firmware 1.05.12, 1.06.18, and 1.06.28, allows remote attackers to discover the cleartext administrative password by reading the "var pass=" line within the HTML source code.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-255
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:westerndigital:my_net_n900:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "89EAAD09-3FBE-42D1-A14B-EC628AE9D890" }, { "criteria": "cpe:2.3:h:westerndigital:my_net_n900c:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E82D5093-96D7-4091-86C0-2B41BF8BF3DD" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:westerndigital:my_net_n750:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "87067A67-D04A-4487-ADA5-7AF2497256AB" } ], "operator": "OR" } ], "operator": "AND" } ]