First published: Wed Aug 28 2013(Updated: )
Samsung Web Viewer for Samsung DVR devices stores credentials in cleartext, which allows context-dependent attackers to obtain sensitive information via vectors involving (1) direct access to a file or (2) the user-setup web page.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Smart Viewer | ||
Samsung DVR |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-3585 is considered a high severity vulnerability due to the exposure of credentials in cleartext.
To fix CVE-2013-3585, update to the latest version of Samsung Smart Viewer or ensure that sensitive credentials are not stored in cleartext.
CVE-2013-3585 affects Samsung DVR devices and the Samsung Smart Viewer application.
An attacker can exploit CVE-2013-3585 to gain access to sensitive information stored in cleartext credentials.
The Samsung DVR is not directly vulnerable to CVE-2013-3585, but the Smart Viewer application that interacts with it is.