CVE-2013-3564
5.3
MEDIUM
CVSS 3.1
EPSS 0.23%
Description
The web interface in VideoLAN VLC media player before 2.0.7 has no access control which allows remote attackers to view directory listings via the 'dir' command or issue other commands without authenticating.
How to fix CVE-2013-3564
To remediate CVE-2013-3564, upgrade the affected package to a fixed version below.
- Debian/vlc—upgrade to 2.0.7-1 or later
Is CVE-2013-3564 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2.0.7-1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.3 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |