CVE-2015-8257
The devtools.sh script in AXIS network cameras allows remote authenticated users to execute arbitrary commands via shell metacharacters in the app parameter to (1) app_license.shtml, (2) app_license_custom.shtml, (3) app_index.shtml, or (4)…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 17.7%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
The devtools.sh script in AXIS network cameras allows remote authenticated users to execute arbitrary commands via shell metacharacters in the app parameter to (1) app_license.shtml, (2) app_license_custom.shtml, (3) app_index.shtml, or (4) app_params.shtml.
- CVSS 3.0
- 8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 17.69% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-77
- Affected
- axis/network camera firmware
- Source
- cret@cert.org
References
- http://packetstormsecurity.com/files/138083/AXIS-Authenticated-Remote-Command-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/92159Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/40171/Exploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/138083/AXIS-Authenticated-Remote-Command-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/92159Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/40171/Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.