CVE-2013-1598: OS Command Injection
Published Jan 24, 2020
·Updated
A Command Injection vulnerability exists in Vivotek PT7135 IP Cameras 0300a and 0400a via the system.ntp parameter to the farseer.out binary file, which cold let a malicious user execute arbitrary code.
Affected Software
3 affected components
Vivotek Pt7135 Firmware=0300a
Vivotek Pt7135 Firmware=0400a
Vivotek PT7135
Event History
Jan 24, 2020
CVE Published
via MITRE·06:32 PM
Data Sourced
via MITRE·06:32 PM
Description
Frequently Asked Questions
1
What is CVE-2013-1598?
CVE-2013-1598 is a Command Injection vulnerability that exists in Vivotek PT7135 IP Cameras 0300a and 0400a.
2
How does CVE-2013-1598 work?
CVE-2013-1598 allows a malicious user to execute arbitrary code by exploiting the system.ntp parameter to the farseer.out binary file.
3
What is the severity of CVE-2013-1598?
CVE-2013-1598 has a severity rating of 8.8 (critical).
4
Which software versions are affected by CVE-2013-1598?
Vivotek PT7135 IP Cameras with firmware versions 0300a and 0400a are affected.
5
How can CVE-2013-1598 be mitigated?
To mitigate CVE-2013-1598, users should update to a patched firmware version provided by Vivotek.