SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2004-2425

Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to execute arbitrary commands via accent (`) and possibly other shell metacharacters in the query string to virtualinput.cgi.

HIGH 7.5EPSS 13.5%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 13.5%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.

Description

Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to execute arbitrary commands via accent (`) and possibly other shell metacharacters in the query string to virtualinput.cgi.

CVSS 2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
13.53% probability · 96th percentile
CISA KEV
Not listed
Affected
axis/2100 network camera · axis/2110 network camera · axis/2120 network camera · axis/2130 ptz network camera · axis/230 mpeg2 video server · axis/2400 video server · axis/2401 video server · axis/2411 video server · axis/2420 network camera · axis/2420 video server · axis/2460 network dvr · axis/2490 serial server · axis/250s video server · axis/storpoint cd
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.