10

CVE-2017-20049

A vulnerability, was found in legacy Axis devices such as P3225 and M3005. This affects an unknown part of the component CGI Script. The manipulation leads to improper privilege management. It is possible to initiate the attack remotely.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Axis ≫ P1204 Firmware Version <= 5.50.4
   Axis ≫ P1204 Version -
Axis ≫ P3225 Firmware Version <= 6.30.1
   Axis ≫ P3225 Version -
Axis ≫ P3367 Firmware Version <= 6.10.1.2
   Axis ≫ P3367 Version -
Axis ≫ M3045 Firmware Version <= 6.15.4.1
   Axis ≫ M3045 Version -
Axis ≫ M3005 Firmware Version <= 5.50.5.7
   Axis ≫ M3005 Version -
Axis ≫ M3007 Firmware Version <= 6.30.1.1
   Axis ≫ M3007 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.51% 0.721
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

https://www.axis.com/dam/public/df/f3/dd/cve-2017-20049-en-US-376956.pdf