2024-12-08 03:06:42 +00:00

98 lines
2.9 KiB
JSON

{
"id": "CVE-2013-6948",
"sourceIdentifier": "cret@cert.org",
"published": "2014-02-22T21:55:09.203",
"lastModified": "2024-11-21T02:00:02.060",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "The peerAddresses API in the Belkin WeMo Home Automation firmware before 3949 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue."
},
{
"lang": "es",
"value": "La API peerAddresses en la versi\u00f3n de firmware anterior a 3949 de Belkin WeMo Home Automation, permite a los atacantes remotos leer archivos arbitrarios por medio de un documento XML que contiene una declaraci\u00f3n de entidad externa en conjunci\u00f3n con una referencia de entidad, relacionada a un problema de tipo XML External Entity (XXE)."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:N/A:N",
"baseScore": 7.8,
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "COMPLETE",
"integrityImpact": "NONE",
"availabilityImpact": "NONE"
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 6.9,
"acInsufInfo": true,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-94"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:belkin:wemo_home_automation_firmware:2769:*:*:*:*:*:*:*",
"matchCriteriaId": "28ACACEF-ADE2-4A54-8F6D-281167EA4A0C"
}
]
}
]
}
],
"references": [
{
"url": "http://www.ioactive.com/pdfs/IOActive_Belkin-advisory-lite.pdf",
"source": "cret@cert.org"
},
{
"url": "http://www.kb.cert.org/vuls/id/656302",
"source": "cret@cert.org",
"tags": [
"US Government Resource"
]
},
{
"url": "http://www.ioactive.com/pdfs/IOActive_Belkin-advisory-lite.pdf",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.kb.cert.org/vuls/id/656302",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"US Government Resource"
]
}
]
}