10

CVE-2017-20049

A vulnerability, was found in legacy Axis devices such as P3225 and M3005. This affects an unknown part of the component CGI Script. The manipulation leads to improper privilege management. It is possible to initiate the attack remotely.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AxisP1204 Firmware Version <= 5.50.4
   AxisP1204 Version-
AxisP3225 Firmware Version <= 6.30.1
   AxisP3225 Version-
AxisP3367 Firmware Version <= 6.10.1.2
   AxisP3367 Version-
AxisM3045 Firmware Version <= 6.15.4.1
   AxisM3045 Version-
AxisM3005 Firmware Version <= 5.50.5.7
   AxisM3005 Version-
AxisM3007 Firmware Version <= 6.30.1.1
   AxisM3007 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.35% 0.569
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.