VulnerabilityModified
CVE-2004-2426
Directory traversal vulnerability in Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to bypass authentication via a ..
MEDIUM 5.0EPSS 4.19%
Does this matter?
Lower severity and a low EPSS score (4.19%). Track it; it rarely justifies an emergency change on its own.
Description
Directory traversal vulnerability in Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to bypass authentication via a .. (dot dot) in an HTTP POST request to ServerManager.srv, then use these privileges to conduct other activities, such as modifying files using editcgi.cgi.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 4.19% probability · 90th percentile
- CISA KEV
- Not listed
- Affected
- axis/2100 network camera · axis/2110 network camera · axis/2120 network camera · axis/2130 ptz network camera · axis/230 mpeg2 video server · axis/2400 video server · axis/2401 video server · axis/2411 video server · axis/2420 network camera · axis/2420 video server · axis/2460 network dvr · axis/2490 serial server · axis/250s video server · axis/storpoint cd
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/fulldisclosure/2004-08/0948.htmlExploit
- http://archives.neohapsis.com/archives/fulldisclosure/2004-08/1282.htmlPatch, Vendor Advisory
- http://secunia.com/advisories/12353Patch, Vendor Advisory
- http://securitytracker.com/id?1011056Exploit, Patch
- http://www.osvdb.org/9122
- http://www.securityfocus.com/bid/11011Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17079
- http://archives.neohapsis.com/archives/fulldisclosure/2004-08/0948.htmlExploit
- http://archives.neohapsis.com/archives/fulldisclosure/2004-08/1282.htmlPatch, Vendor Advisory
- http://secunia.com/advisories/12353Patch, Vendor Advisory
- http://securitytracker.com/id?1011056Exploit, Patch
- http://www.osvdb.org/9122
- http://www.securityfocus.com/bid/11011Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17079
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.