Page 2 of 9 results (0.003 seconds)

CVSS: 7.5EPSS: 0%CPEs: 780EXPL: 1

An issue was discovered in multiple models of Axis IP Cameras. There is an Incorrect Size Calculation. Se ha descubierto un problema en múltiples modelos de las cámaras IP Axis. Existe un cálculo de tamaño incorrecto. Axis Cameras suffer from authorization bypass, unrestricted dbus access, command injection, denial of service, and information disclosure vulnerabilities. • https://blog.vdoo.com/2018/06/18/vdoo-discovers-significant-vulnerabilities-in-axis-cameras https://www.axis.com/files/faq/Advisory_ACV-128401.pdf https://www.axis.com/files/sales/ACV-128401_Affected_Product_List.pdf • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 10.0EPSS: 9%CPEs: 780EXPL: 2

An issue was discovered in multiple models of Axis IP Cameras. There is Shell Command Injection. Se ha descubierto un problema en múltiples modelos de las cámaras IP Axis. Existe inyección de comandos Shell. Axis Cameras suffer from authorization bypass, unrestricted dbus access, command injection, denial of service, and information disclosure vulnerabilities. • https://www.exploit-db.com/exploits/45100 https://blog.vdoo.com/2018/06/18/vdoo-discovers-significant-vulnerabilities-in-axis-cameras https://www.axis.com/files/faq/Advisory_ACV-128401.pdf https://www.axis.com/files/sales/ACV-128401_Affected_Product_List.pdf • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVSS: 7.6EPSS: 0%CPEs: 2EXPL: 0

An issue was discovered on AXIS M1033-W (IP camera) Firmware version 5.40.5.1 devices. The upload web page doesn't verify the file type, and an attacker can upload a webshell by making a fileUpload.shtml request for a custom .shtml file, which is interpreted by the Apache HTTP Server mod_include module with "<!--#exec cmd=" support. The file needs to include a specific string to meet the internal system architecture. After the webshell upload, an attacker can use the webshell to perform remote code execution such as running a system command (ls, ping, cat /etc/passwd, etc.). • https://www.slideshare.net/secret/pRWQOOe6rN8Iyb • CWE-434: Unrestricted Upload of File with Dangerous Type •

CVSS: 7.5EPSS: 0%CPEs: 2EXPL: 1

An issue was discovered on AXIS M1033-W (IP camera) Firmware version 5.40.5.1 devices. They don't employ a suitable mechanism to prevent a DoS attack, which leads to a response time delay. An attacker can use the hping3 tool to perform an IPv4 flood attack, and the services are interrupted from attack start to end. Se ha descubierto un problema en los dispositivos AXIS M1033-W (cámara IP) con versión de firmware 5.40.5.1. No emplean un mecanismo adecuado de prevención de ataques de denegación de servicio (DoS), lo que conduce a un retraso en los tiempos de respuesta. • https://www.slideshare.net/secret/HpAEwK5qo5U4b1 • CWE-20: Improper Input Validation •