Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-20049


A vulnerability, was found in legacy Axis devices such as P3225 and M3005. This affects an unknown part of the component CGI Script. The manipulation leads to improper privilege management. It is possible to initiate the attack remotely.


Published

2022-06-15T18:15:08.470

Last Modified

2024-11-21T03:22:31.257

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-269

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System axis p1204_firmware ≤ 5.50.4 Yes
Hardware axis p1204 - No
Operating System axis p3225_firmware ≤ 6.30.1 Yes
Hardware axis p3225 - No
Operating System axis p3367_firmware ≤ 6.10.1.2 Yes
Hardware axis p3367 - No
Operating System axis m3045_firmware ≤ 6.15.4.1 Yes
Hardware axis m3045 - No
Operating System axis m3005_firmware ≤ 5.50.5.7 Yes
Hardware axis m3005 - No
Operating System axis m3007_firmware ≤ 6.30.1.1 Yes
Hardware axis m3007 - No

References