SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2007-5213

Multiple cross-site request forgery (CSRF) vulnerabilities in the AXIS 2100 Network Camera 2.02 with firmware 2.43 and earlier allow remote attackers to perform actions as administrators, as demonstrated by (1) an SMTP server change through the…

HIGH 9.3EPSS 1.69%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.69%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in the AXIS 2100 Network Camera 2.02 with firmware 2.43 and earlier allow remote attackers to perform actions as administrators, as demonstrated by (1) an SMTP server change through the conf_SMTP_MailServer1 parameter to ServerManager.srv and (2) a hostname change through the conf_Network_HostName parameter on the Network page.

CVSS 2.0
9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS
1.69% probability · 76th percentile
CISA KEV
Not listed
Weakness
CWE-352
Affected
axis/2100 network camera · axis/2100 network camera firmware
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.