VulnerabilityModified
CVE-2004-2425
Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to execute arbitrary commands via accent (`) and possibly other shell metacharacters in the query string to virtualinput.cgi.
HIGH 7.5EPSS 13.5%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 13.5%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to execute arbitrary commands via accent (`) and possibly other shell metacharacters in the query string to virtualinput.cgi.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 13.53% probability · 96th percentile
- CISA KEV
- Not listed
- Affected
- axis/2100 network camera · axis/2110 network camera · axis/2120 network camera · axis/2130 ptz network camera · axis/230 mpeg2 video server · axis/2400 video server · axis/2401 video server · axis/2411 video server · axis/2420 network camera · axis/2420 video server · axis/2460 network dvr · axis/2490 serial server · axis/250s video server · axis/storpoint cd
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/fulldisclosure/2004-08/0948.htmlExploit
- http://archives.neohapsis.com/archives/fulldisclosure/2004-08/1282.htmlPatch, Vendor Advisory
- http://secunia.com/advisories/12353Patch, Vendor Advisory
- http://securitytracker.com/id?1011056Exploit, Patch
- http://www.osvdb.org/9121
- http://www.securityfocus.com/bid/11011Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17076
- http://archives.neohapsis.com/archives/fulldisclosure/2004-08/0948.htmlExploit
- http://archives.neohapsis.com/archives/fulldisclosure/2004-08/1282.htmlPatch, Vendor Advisory
- http://secunia.com/advisories/12353Patch, Vendor Advisory
- http://securitytracker.com/id?1011056Exploit, Patch
- http://www.osvdb.org/9121
- http://www.securityfocus.com/bid/11011Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17076
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.