CRITICAL · 9.8

CVE-2018-10660

An issue was discovered in multiple models of Axis IP Cameras. There is Shell Command Injection.

Vulnerability Description

An issue was discovered in multiple models of Axis IP Cameras. There is Shell Command Injection.

CVSS Score

9.8

CRITICAL

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
AxisA1001 Firmware< 1.65.1
AxisA1001-
AxisA8004-V Firmware< 1.65.2
AxisA8004-V-
AxisA8105-E Firmware< 1.65.2
AxisA8105-E-
AxisA9161 Firmware< 1.65.0
AxisA9161-
AxisA9188 Firmware< 1.65.0
AxisA9188-
AxisA9188-V Firmware< 1.65.0
AxisA9188-V-
AxisC1004-E Firmware< 1.81.040.1
AxisC1004-E-
AxisC2005 Firmware< 1.81.040.1
AxisC2005-
AxisC3003-E Firmware< 1.81.040.1
AxisC3003-E-
AxisC8033 Firmware< 1.81.040.1
AxisC8033-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-10660?

CVE-2018-10660 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An issue was discovered in multiple models of Axis IP Cameras. There is Shell Command Injection.

How severe is CVE-2018-10660?

CVE-2018-10660 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2018-10660?

Check the references section above for vendor advisories and patch information. Affected products include: Axis A1001 Firmware, Axis A1001, Axis A8004-V Firmware, Axis A8004-V, Axis A8105-E Firmware.