HIGH · 8.8

CVE-2015-8257

The devtools.sh script in AXIS network cameras allows remote authenticated users to execute arbitrary commands via shell metacharacters in the app parameter to (1) app_license.shtml, (2) app_license_c...

Vulnerability Description

The devtools.sh script in AXIS network cameras allows remote authenticated users to execute arbitrary commands via shell metacharacters in the app parameter to (1) app_license.shtml, (2) app_license_custom.shtml, (3) app_index.shtml, or (4) app_params.shtml.

CVSS Score

8.8

HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
AxisNetwork Camera Firmware-
AxisCannon Network Camera-
AxisExplosion-Protected Camera-
AxisFixed Box Camera-
AxisFixed Bullet Camera-
AxisFixed Dome Camera-
AxisModular Camera-
AxisOnboard Camera-
AxisPanoramic Camera-
AxisPtz Camera-
AxisThermal Camera-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-8257?

CVE-2015-8257 is a vulnerability with a CVSS score of 8.8 (HIGH). The devtools.sh script in AXIS network cameras allows remote authenticated users to execute arbitrary commands via shell metacharacters in the app parameter to (1) app_license.shtml, (2) app_license_c...

How severe is CVE-2015-8257?

CVE-2015-8257 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-8257?

Check the references section above for vendor advisories and patch information. Affected products include: Axis Network Camera Firmware, Axis Cannon Network Camera, Axis Explosion-Protected Camera, Axis Fixed Box Camera, Axis Fixed Bullet Camera.