// For flags

CVE-2007-5213

 

Severity Score

9.3
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Multiple cross-site request forgery (CSRF) vulnerabilities in the AXIS 2100 Network Camera 2.02 with firmware 2.43 and earlier allow remote attackers to perform actions as administrators, as demonstrated by (1) an SMTP server change through the conf_SMTP_MailServer1 parameter to ServerManager.srv and (2) a hostname change through the conf_Network_HostName parameter on the Network page.

Múltiples vulnerabilidades de falsificación de petición en sitios cruzados (CSRF) en AXIS 2100 Network Camera 2.02 con firmware 2.43 y anteriores permite a atacantes remotos llevar a cabo acciones como administrador, como ha sido demostrado por (1) un cambio del servidor SMTP a través del parámetro conf_SMTP_MailServer1 a ServerManager.srv y (2) un cambio del nombre de máquina a través del parámetro conf_Network_HostName en la página Network.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2007-10-04 CVE Reserved
  • 2007-10-04 CVE Published
  • 2024-08-07 CVE Updated
  • 2024-08-07 First Exploit
  • 2024-09-14 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Axis
Search vendor "Axis"
2100 Network Camera
Search vendor "Axis" for product "2100 Network Camera"
2.02
Search vendor "Axis" for product "2100 Network Camera" and version "2.02"
-
Affected
Axis
Search vendor "Axis"
2100 Network Camera Firmware
Search vendor "Axis" for product "2100 Network Camera Firmware"
<= 2.42
Search vendor "Axis" for product "2100 Network Camera Firmware" and version " <= 2.42"
-
Affected