ID

VAR-201311-0283


CVE

CVE-2013-4713


TITLE

RockDisk vulnerable to cross-site scripting

Trust: 0.8

sources: JVNDB: JVNDB-2013-000096

DESCRIPTION

Cross-site scripting (XSS) vulnerability in I-O DATA DEVICE RockDisk with firmware before 1.05e1-2.0.5 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. RockDisk provided by I-O DATA DEVICE, INC. are LAN connectable hard disk drives. RockDisk contains a cross-site scripting vulnerability. Yuji Tounai of bogus.jp reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.An arbitrary script may be executed on the user's web browser. I-O DATA RockDisk NAS incorrectly filters data returned to users, allowing remote attackers to exploit vulnerabilities to build malicious URIs, entice users to parse, obtain sensitive information, or hijack user sessions. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks

Trust: 2.52

sources: NVD: CVE-2013-4713 // JVNDB: JVNDB-2013-000096 // CNVD: CNVD-2013-14194 // BID: 63392 // VULHUB: VHN-64715

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2013-14194

AFFECTED PRODUCTS

vendor:iodatamodel:rockdiskscope:eqversion:1.04n-2.0.1

Trust: 1.6

vendor:iodatamodel:rockdiskscope:eqversion:1.03v3-1.13

Trust: 1.6

vendor:iodatamodel:rockdiskscope:eqversion:1.04a-1.2

Trust: 1.6

vendor:iodatamodel:rockdiskscope:eqversion:1.03w-1.14

Trust: 1.6

vendor:iodatamodel:rockdiskscope:eqversion:1.04m-2.0.1

Trust: 1.6

vendor:iodatamodel:rockdiskscope:eqversion:1.03y-1.16

Trust: 1.6

vendor:iodatamodel:rockdiskscope:eqversion:1.04r3-2.0.1

Trust: 1.6

vendor:iodatamodel:rockdiskscope:eqversion:1.04t-2.0.2

Trust: 1.6

vendor:iodatamodel:rockdiskscope:eqversion:1.04b-1.21

Trust: 1.6

vendor:iodatamodel:rockdiskscope:eqversion: -

Trust: 1.0

vendor:iodatamodel:rockdiskscope:lteversion:1.05c-2.0.3

Trust: 1.0

vendor:iodatamodel:rockdiskscope:eqversion:1.04d-2.0.1

Trust: 1.0

vendor:i o data devicemodel:rockdiskscope: - version: -

Trust: 0.8

vendor:i o data devicemodel:rockdiskscope:lteversion:version 1.05e1-2.0.5

Trust: 0.8

vendor:i omodel:data rockdisk nas 1.05c-2.0.3scope: - version: -

Trust: 0.6

vendor:iodatamodel:rockdiskscope:eqversion:1.05c-2.0.3

Trust: 0.6

sources: CNVD: CNVD-2013-14194 // JVNDB: JVNDB-2013-000096 // CNNVD: CNNVD-201310-720 // NVD: CVE-2013-4713

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2013-4713
value: LOW

Trust: 1.0

IPA: JVNDB-2013-000096
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2013-14194
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201310-720
value: LOW

Trust: 0.6

VULHUB: VHN-64715
value: LOW

Trust: 0.1

nvd@nist.gov: CVE-2013-4713
severity: LOW
baseScore: 3.5
vectorString: AV:N/AC:M/AU:S/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 6.8
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

IPA: JVNDB-2013-000096
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

CNVD: CNVD-2013-14194
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-64715
severity: LOW
baseScore: 3.5
vectorString: AV:N/AC:M/AU:S/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 6.8
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CNVD: CNVD-2013-14194 // VULHUB: VHN-64715 // JVNDB: JVNDB-2013-000096 // CNNVD: CNNVD-201310-720 // NVD: CVE-2013-4713

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.9

sources: VULHUB: VHN-64715 // JVNDB: JVNDB-2013-000096 // NVD: CVE-2013-4713

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201310-720

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-201310-720

CONFIGURATIONS

sources: JVNDB: JVNDB-2013-000096

PATCH

title:I-O DATA DEVICE, INC. websiteurl:http://www.ioplaza.jp/shop/contents/rdiskmanual.aspx

Trust: 0.8

title:I-O DATA RockDisk NAS has patches for unidentified cross-site scripting vulnerabilitiesurl:https://www.cnvd.org.cn/patchInfo/show/40628

Trust: 0.6

sources: CNVD: CNVD-2013-14194 // JVNDB: JVNDB-2013-000096

EXTERNAL IDS

db:JVNDBid:JVNDB-2013-000096

Trust: 3.9

db:NVDid:CVE-2013-4713

Trust: 3.4

db:JVNid:JVN74608669

Trust: 3.1

db:BIDid:63392

Trust: 1.6

db:SECUNIAid:55463

Trust: 0.6

db:CNVDid:CNVD-2013-14194

Trust: 0.6

db:JVNid:JVN#74608669

Trust: 0.6

db:CNNVDid:CNNVD-201310-720

Trust: 0.6

db:VULHUBid:VHN-64715

Trust: 0.1

sources: CNVD: CNVD-2013-14194 // VULHUB: VHN-64715 // BID: 63392 // JVNDB: JVNDB-2013-000096 // CNNVD: CNNVD-201310-720 // NVD: CVE-2013-4713

REFERENCES

url:http://jvn.jp/en/jp/jvn74608669/index.html

Trust: 3.1

url:http://jvndb.jvn.jp/jvndb/jvndb-2013-000096

Trust: 3.1

url:http://www.ioplaza.jp/shop/contents/rdiskmanual.aspx

Trust: 1.7

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2013-4713

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2013-4713

Trust: 0.8

url:http://secunia.com/advisories/55463/

Trust: 0.6

url:http://www.securityfocus.com/bid/63392

Trust: 0.6

sources: CNVD: CNVD-2013-14194 // VULHUB: VHN-64715 // JVNDB: JVNDB-2013-000096 // CNNVD: CNNVD-201310-720 // NVD: CVE-2013-4713

CREDITS

Yuji Tounai of bogus.jp

Trust: 0.9

sources: BID: 63392 // CNNVD: CNNVD-201310-720

SOURCES

db:CNVDid:CNVD-2013-14194
db:VULHUBid:VHN-64715
db:BIDid:63392
db:JVNDBid:JVNDB-2013-000096
db:CNNVDid:CNNVD-201310-720
db:NVDid:CVE-2013-4713

LAST UPDATE DATE

2025-04-11T23:10:35.095000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2013-14194date:2013-11-01T00:00:00
db:VULHUBid:VHN-64715date:2013-11-21T00:00:00
db:BIDid:63392date:2013-11-01T01:01:00
db:JVNDBid:JVNDB-2013-000096date:2014-07-02T00:00:00
db:CNNVDid:CNNVD-201310-720date:2013-11-04T00:00:00
db:NVDid:CVE-2013-4713date:2025-04-11T00:51:21.963

SOURCES RELEASE DATE

db:CNVDid:CNVD-2013-14194date:2013-11-01T00:00:00
db:VULHUBid:VHN-64715date:2013-11-01T00:00:00
db:BIDid:63392date:2013-10-29T00:00:00
db:JVNDBid:JVNDB-2013-000096date:2013-10-29T00:00:00
db:CNNVDid:CNNVD-201310-720date:2013-10-31T00:00:00
db:NVDid:CVE-2013-4713date:2013-11-01T02:55:04.933