CVE-2013-1602 is an information disclosure vulnerability affecting numerous D-Link IP camera models, including the DCS-5635, DCS-1100L, and DCS-2102. The flaw stems from insufficient validation of authentication cookies for RTSP sessions, potentially allowing unauthorized access to video streams. With a CVSS score of 7.5 (High), this vulnerability is easily exploitable over the network with low attack complexity, leading to a high impact on confidentiality. While not listed on CISA's KEV catalog, exploit code is publicly available via ExploitDB, and it has garnered significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.02CPE matchmatch criteria | cpe:2.3:o:dlink:dcs-3411_firmware:1.02:*:*:*:*:*:*:* | ||
1.02CPE matchmatch criteria | cpe:2.3:o:dlink:dcs-3430_firmware:1.02:*:*:*:*:*:*:* | ||
1.01CPE matchmatch criteria | cpe:2.3:o:dlink:dcs-5605_firmware:1.01:*:*:*:*:*:*:* | ||
1.01CPE matchmatch criteria | cpe:2.3:o:dlink:dcs-5635_firmware:1.01:*:*:*:*:*:*:* | ||
1.04CPE matchmatch criteria | cpe:2.3:o:dlink:dcs-1100l_firmware:1.04:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.