HIGH · 10.0

CVE-2003-0240

The web-based administration capability for various Axis Network Camera products allows remote attackers to bypass access restrictions and modify configuration via an HTTP request to the admin/admin.s...

Vulnerability Description

The web-based administration capability for various Axis Network Camera products allows remote attackers to bypass access restrictions and modify configuration via an HTTP request to the admin/admin.shtml containing a leading // (double slash).

CVSS Score

10.0

HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
Axis2100 Network Camera<= 2.32
Axis2110 Network Camera<= 2.32
Axis2120 Network Camera<= 2.32
Axis2130 Ptz Network Camera<= 2.32
Axis2400 Video Server<= 2.32
Axis2401 Video Server<= 2.32
Axis2420 Network Camera<= 2.32
Axis2460 Network Dvr<= 3.00
Axis250S Video Server<= 3.02

References

FAQ

What is CVE-2003-0240?

CVE-2003-0240 is a vulnerability with a CVSS score of 10.0 (HIGH). The web-based administration capability for various Axis Network Camera products allows remote attackers to bypass access restrictions and modify configuration via an HTTP request to the admin/admin.s...

How severe is CVE-2003-0240?

CVE-2003-0240 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2003-0240?

Check the references section above for vendor advisories and patch information. Affected products include: Axis 2100 Network Camera, Axis 2110 Network Camera, Axis 2120 Network Camera, Axis 2130 Ptz Network Camera, Axis 2400 Video Server.