SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-10660

There is Shell Command Injection.

CRITICAL 9.8EPSS 82.1%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 82.1%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.

Description

An issue was discovered in multiple models of Axis IP Cameras. There is Shell Command Injection.

CVSS 3.0
9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
82.08% probability · 100th percentile
CISA KEV
Not listed
Weakness
CWE-78
Affected
axis/a1001 firmware · axis/a8004-v firmware · axis/a8105-e firmware · axis/a9161 firmware · axis/a9188 firmware · axis/a9188-v firmware · axis/c1004-e firmware · axis/c2005 firmware · axis/c3003-e firmware · axis/c8033 firmware · axis/companion bullet le firmware · axis/companion c360 firmware · axis/companion cube l firmware · axis/companion cube lw firmware · axis/companion dome v firmware · axis/companion dome wv firmware · axis/companion eye l firmware · axis/companion eye lve firmware · axis/companion recorder 4ch firmware · axis/companion recorder 8ch firmware · +40 more
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.