CVE-2018-9157
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered on AXIS M1033-W (IP camera) Firmware version 5.40.5.1 devices. The upload web page doesn't verify the file type, and an attacker can upload a webshell by making a fileUpload.shtml request for a custom .shtml file, which is interpreted by the Apache HTTP Server mod_include module with "<!--#exec cmd=" support. The file needs to include a specific string to meet the internal system architecture. After the webshell upload, an attacker can use the webshell to perform remote code execution such as running a system command (ls, ping, cat /etc/passwd, etc.). NOTE: the vendor reportedly indicates that this is an intended feature or functionality
** EN DISPUTA ** Se ha descubierto un problema en los dispositivos AXIS M1033-W (cámara IP) con versión de firmware 5.40.5.1. La página web de subida no verifica el tipo de archivo y un atacante puede subir un webshell haciendo una petición fileUpload.shtml para un archivo .shtml personalizado, lo cual se interpreta en el módulo mod_include de Apache HTTP Server con soporte #exec cmd. El archivo necesita incluir una cadena específica para cumplir con la arquitectura interna del sistema. Después de la carga del webshell, un atacante puede usar la webshell para realizar la ejecución remota de código, como ejecutar un comando del sistema (ls, ping, cat /etc/passwd, etc.). NOTA: el proveedor indica que se trata de una característica o funcionalidad prevista.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-03-31 CVE Reserved
- 2018-04-01 CVE Published
- 2024-08-05 CVE Updated
- 2024-11-02 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-434: Unrestricted Upload of File with Dangerous Type
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://www.slideshare.net/secret/pRWQOOe6rN8Iyb | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Axis Search vendor "Axis" | M1033-w Firmware Search vendor "Axis" for product "M1033-w Firmware" | 5.40.5.1 Search vendor "Axis" for product "M1033-w Firmware" and version "5.40.5.1" | - |
Affected
| in | Axis Search vendor "Axis" | M1033-w Search vendor "Axis" for product "M1033-w" | - | - |
Safe
|