Directory traversal vulnerability in Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to bypass authentication via a .. (dot dot) in an HTTP POST request to ServerManager.srv, then use these privileges to conduct other activities, such as modifying files using editcgi.cgi.
Name | Vendor | Start Version | End Version |
---|---|---|---|
2100_network_camera | Axis | 2.12 (including) | 2.12 (including) |
2100_network_camera | Axis | 2.30 (including) | 2.30 (including) |
2100_network_camera | Axis | 2.31 (including) | 2.31 (including) |
2100_network_camera | Axis | 2.32 (including) | 2.32 (including) |
2100_network_camera | Axis | 2.33 (including) | 2.33 (including) |
2100_network_camera | Axis | 2.34 (including) | 2.34 (including) |
2100_network_camera | Axis | 2.40 (including) | 2.40 (including) |
2100_network_camera | Axis | 2.41 (including) | 2.41 (including) |
2110_network_camera | Axis | 2.12 (including) | 2.12 (including) |
2110_network_camera | Axis | 2.30 (including) | 2.30 (including) |
2110_network_camera | Axis | 2.31 (including) | 2.31 (including) |
2110_network_camera | Axis | 2.32 (including) | 2.32 (including) |
2110_network_camera | Axis | 2.34 (including) | 2.34 (including) |
2110_network_camera | Axis | 2.40 (including) | 2.40 (including) |
2110_network_camera | Axis | 2.41 (including) | 2.41 (including) |
2120_network_camera | Axis | 2.12 (including) | 2.12 (including) |
2120_network_camera | Axis | 2.30 (including) | 2.30 (including) |
2120_network_camera | Axis | 2.31 (including) | 2.31 (including) |
2120_network_camera | Axis | 2.32 (including) | 2.32 (including) |
2120_network_camera | Axis | 2.34 (including) | 2.34 (including) |
2120_network_camera | Axis | 2.40 (including) | 2.40 (including) |
2120_network_camera | Axis | 2.41 (including) | 2.41 (including) |
2130_ptz_network_camera | Axis | 2.30 (including) | 2.30 (including) |
2130_ptz_network_camera | Axis | 2.31 (including) | 2.31 (including) |
2130_ptz_network_camera | Axis | 2.32 (including) | 2.32 (including) |
2130_ptz_network_camera | Axis | 2.34 (including) | 2.34 (including) |
2130_ptz_network_camera | Axis | 2.40 (including) | 2.40 (including) |
230_mpeg2_video_server | Axis | 3.11 (including) | 3.11 (including) |
2400_video_server | Axis | 1.1 (including) | 1.1 (including) |
2400_video_server | Axis | 1.2 (including) | 1.2 (including) |
2400_video_server | Axis | 1.10 (including) | 1.10 (including) |
2400_video_server | Axis | 1.11 (including) | 1.11 (including) |
2400_video_server | Axis | 1.12 (including) | 1.12 (including) |
2400_video_server | Axis | 1.15 (including) | 1.15 (including) |
2400_video_server | Axis | 2.0 (including) | 2.0 (including) |
2400_video_server | Axis | 2.20 (including) | 2.20 (including) |
2400_video_server | Axis | 2.30 (including) | 2.30 (including) |
2400_video_server | Axis | 2.31 (including) | 2.31 (including) |
2400_video_server | Axis | 2.32 (including) | 2.32 (including) |
2400_video_server | Axis | 2.33 (including) | 2.33 (including) |
2400_video_server | Axis | 2.34 (including) | 2.34 (including) |
2400_video_server | Axis | 3.11 (including) | 3.11 (including) |
2400_video_server | Axis | 3.12 (including) | 3.12 (including) |
2401_video_server | Axis | 1.0_1 (including) | 1.0_1 (including) |
2401_video_server | Axis | 1.15 (including) | 1.15 (including) |
2401_video_server | Axis | 2.20 (including) | 2.20 (including) |
2401_video_server | Axis | 2.30 (including) | 2.30 (including) |
2401_video_server | Axis | 2.31 (including) | 2.31 (including) |
2401_video_server | Axis | 2.32 (including) | 2.32 (including) |
2401_video_server | Axis | 2.33 (including) | 2.33 (including) |
2401_video_server | Axis | 2.34 (including) | 2.34 (including) |
2401_video_server | Axis | 3.12 (including) | 3.12 (including) |
2401_video_server | Axis | 3.13 (including) | 3.13 (including) |
2411_video_server | Axis | 3.12 (including) | 3.12 (including) |
2411_video_server | Axis | 3.13 (including) | 3.13 (including) |
2420_network_camera | Axis | 2.12 (including) | 2.12 (including) |
2420_network_camera | Axis | 2.30 (including) | 2.30 (including) |
2420_network_camera | Axis | 2.31 (including) | 2.31 (including) |
2420_network_camera | Axis | 2.32 (including) | 2.32 (including) |
2420_network_camera | Axis | 2.33 (including) | 2.33 (including) |
2420_network_camera | Axis | 2.34 (including) | 2.34 (including) |
2420_network_camera | Axis | 2.40 (including) | 2.40 (including) |
2420_network_camera | Axis | 2.41 (including) | 2.41 (including) |
2420_video_server | Axis | 2.32 (including) | 2.32 (including) |
2420_video_server | Axis | 2.34 (including) | 2.34 (including) |
2460_network_dvr | Axis | * | * |
2460_network_dvr | Axis | 3.10 (including) | 3.10 (including) |
2460_network_dvr | Axis | 3.11 (including) | 3.11 (including) |
2490_serial_server | Axis | * | * |
2490_serial_server | Axis | 2.11.3 (including) | 2.11.3 (including) |
250s_video_server | Axis | * | * |
250s_video_server | Axis | 3.03 (including) | 3.03 (including) |
250s_video_server | Axis | 3.10 (including) | 3.10 (including) |
Storpoint_cd | Axis | * | * |