CRITICAL · 9.8

CVE-2017-20049

A vulnerability, was found in legacy Axis devices such as P3225 and M3005. This affects an unknown part of the component CGI Script. The manipulation leads to improper privilege management. It is poss...

Vulnerability Description

A vulnerability, was found in legacy Axis devices such as P3225 and M3005. This affects an unknown part of the component CGI Script. The manipulation leads to improper privilege management. It is possible to initiate the attack remotely.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
AxisP1204 Firmware<= 5.50.4
AxisP1204-
AxisP3225 Firmware<= 6.30.1
AxisP3225-
AxisP3367 Firmware<= 6.10.1.2
AxisP3367-
AxisM3045 Firmware<= 6.15.4.1
AxisM3045-
AxisM3005 Firmware<= 5.50.5.7
AxisM3005-
AxisM3007 Firmware<= 6.30.1.1
AxisM3007-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2017-20049?

CVE-2017-20049 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A vulnerability, was found in legacy Axis devices such as P3225 and M3005. This affects an unknown part of the component CGI Script. The manipulation leads to improper privilege management. It is poss...

How severe is CVE-2017-20049?

CVE-2017-20049 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2017-20049?

Check the references section above for vendor advisories and patch information. Affected products include: Axis P1204 Firmware, Axis P1204, Axis P3225 Firmware, Axis P3225, Axis P3367 Firmware.