SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-20049

A vulnerability, was found in legacy Axis devices such as P3225 and M3005.

CRITICAL 9.8EPSS 1.56%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.56%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

A vulnerability, was found in legacy Axis devices such as P3225 and M3005. This affects an unknown part of the component CGI Script. The manipulation leads to improper privilege management. It is possible to initiate the attack remotely.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
1.56% probability · 74th percentile
CISA KEV
Not listed
Weakness
CWE-269
Affected
axis/p1204 firmware · axis/p3225 firmware · axis/p3367 firmware · axis/m3045 firmware · axis/m3005 firmware · axis/m3007 firmware
Source
product-security@axis.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.