A vulnerability, which was classified as critical, was found in AXIS P1204, P3225, P3367, M3045, M3005 and M3007. This affects an unknown part of the component CGI Script. The manipulation leads to improper privilege management. It is possible to initiate the attack remotely. It is recommended to upgrade the affected component.
References
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
History
21 Nov 2024, 03:22
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.axis.com/dam/public/df/f3/dd/cve-2017-20049-en-US-376956.pdf - |
24 Jun 2022, 19:11
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-269 | |
References | (N/A) https://vuldb.com/?id.98913 - Third Party Advisory | |
References | (N/A) http://seclists.org/fulldisclosure/2017/Mar/41 - Exploit, Mailing List, Third Party Advisory | |
CVSS |
v2 : v3 : |
v2 : 10.0
v3 : 9.8 |
CPE | cpe:2.3:h:axis:p3367:-:*:*:*:*:*:*:* cpe:2.3:o:axis:p1204_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:axis:p3225_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:axis:m3005:-:*:*:*:*:*:*:* cpe:2.3:h:axis:m3007:-:*:*:*:*:*:*:* cpe:2.3:o:axis:m3007_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:axis:p3367_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:axis:m3045_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:axis:p3225:-:*:*:*:*:*:*:* cpe:2.3:h:axis:m3045:-:*:*:*:*:*:*:* cpe:2.3:h:axis:p1204:-:*:*:*:*:*:*:* cpe:2.3:o:axis:m3005_firmware:*:*:*:*:*:*:*:* |
15 Jun 2022, 18:46
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-06-15 18:15
Updated : 2024-11-21 03:22
NVD link : CVE-2017-20049
Mitre link : CVE-2017-20049
CVE.ORG link : CVE-2017-20049
JSON object : View
Products Affected
axis
- p3225
- p3367
- m3007
- p3225_firmware
- m3005_firmware
- m3007_firmware
- m3045_firmware
- p3367_firmware
- p1204
- p1204_firmware
- m3005
- m3045
CWE
CWE-269
Improper Privilege Management