ID

VAR-200412-0392


CVE

CVE-2004-2426


TITLE

Axis Network Camera And Video Server Multiple Vulnerabilities

Trust: 0.9

sources: BID: 11011 // CNNVD: CNNVD-200412-745

DESCRIPTION

Directory traversal vulnerability in Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to bypass authentication via a .. (dot dot) in an HTTP POST request to ServerManager.srv, then use these privileges to conduct other activities, such as modifying files using editcgi.cgi. A shell metacharacter command-execution vulnerability allows an anonymous user to download the contents of the '/etc/passwd' file on the device. Other commands are also likely to work, facilitating other attacks. This issue is reported to affect: - Axis 2100, 2110, 2120, 2420 network cameras with firmware versions 2.34 thru 2.40 - Axis 2130 network cameras - Axis 2401 and 2401 video servers 2. A directory-traversal vulnerability in HTTP POST requests. This attack is demonstrated by an anonymous user calling protected administration scripts. This bypasses authentication checks and gives anonymous users remote adminitration of the devices. This issue is reported to affect: - Axis 2100, 2110, 2120, 2420 network cameras with firmware versions 2.12 thru 2.40 - Axis 2130 network cameras - Axis 2401,and 2401 video servers 3. A hardcoded backdoor administrative-user issue allows remote attackers to administer affected devices. This likely cannot be disabled. This issue is reported to affect: - Axis StorePoint CD E100 CD-ROM Server with firmware version 5.30 Other products and versions of firmware are likely affected by one or more of these vulnerabilities

Trust: 1.26

sources: NVD: CVE-2004-2426 // BID: 11011 // VULHUB: VHN-10854

AFFECTED PRODUCTS

vendor:axismodel:2400 video serverscope:eqversion:2.32

Trust: 1.6

vendor:axismodel:2401 video serverscope:eqversion:1.0_1

Trust: 1.6

vendor:axismodel:2401 video serverscope:eqversion:2.30

Trust: 1.6

vendor:axismodel:2400 video serverscope:eqversion:3.12

Trust: 1.6

vendor:axismodel:2401 video serverscope:eqversion:2.20

Trust: 1.6

vendor:axismodel:2400 video serverscope:eqversion:2.31

Trust: 1.6

vendor:axismodel:2400 video serverscope:eqversion:2.34

Trust: 1.6

vendor:axismodel:2400 video serverscope:eqversion:2.33

Trust: 1.6

vendor:axismodel:2401 video serverscope:eqversion:1.15

Trust: 1.6

vendor:axismodel:2400 video serverscope:eqversion:3.11

Trust: 1.6

vendor:axismodel:2400 video serverscope:eqversion:1.12

Trust: 1.0

vendor:axismodel:2130 ptz network camerascope:eqversion:2.30

Trust: 1.0

vendor:axismodel:2120 network camerascope:eqversion:2.32

Trust: 1.0

vendor:axismodel:2400 video serverscope:eqversion:2.0

Trust: 1.0

vendor:axismodel:2460 network dvrscope:eqversion:3.11

Trust: 1.0

vendor:axismodel:2420 network camerascope:eqversion:2.12

Trust: 1.0

vendor:axismodel:2400 video serverscope:eqversion:1.2

Trust: 1.0

vendor:axismodel:2411 video serverscope:eqversion:3.12

Trust: 1.0

vendor:axismodel:2420 network camerascope:eqversion:2.30

Trust: 1.0

vendor:axismodel:2110 network camerascope:eqversion:2.34

Trust: 1.0

vendor:axismodel:2100 network camerascope:eqversion:2.33

Trust: 1.0

vendor:axismodel:2120 network camerascope:eqversion:2.40

Trust: 1.0

vendor:axismodel:2490 serial serverscope:eqversion:*

Trust: 1.0

vendor:axismodel:2130 ptz network camerascope:eqversion:2.34

Trust: 1.0

vendor:axismodel:2400 video serverscope:eqversion:1.10

Trust: 1.0

vendor:axismodel:2420 video serverscope:eqversion:2.32

Trust: 1.0

vendor:axismodel:250s video serverscope:eqversion:3.10

Trust: 1.0

vendor:axismodel:2100 network camerascope:eqversion:2.31

Trust: 1.0

vendor:axismodel:2420 network camerascope:eqversion:2.34

Trust: 1.0

vendor:axismodel:2120 network camerascope:eqversion:2.41

Trust: 1.0

vendor:axismodel:250s video serverscope:eqversion:*

Trust: 1.0

vendor:axismodel:2100 network camerascope:eqversion:2.32

Trust: 1.0

vendor:axismodel:2401 video serverscope:eqversion:2.34

Trust: 1.0

vendor:axismodel:2420 network camerascope:eqversion:2.41

Trust: 1.0

vendor:axismodel:2120 network camerascope:eqversion:2.12

Trust: 1.0

vendor:axismodel:2120 network camerascope:eqversion:2.30

Trust: 1.0

vendor:axismodel:2110 network camerascope:eqversion:2.31

Trust: 1.0

vendor:axismodel:2100 network camerascope:eqversion:2.40

Trust: 1.0

vendor:axismodel:2420 network camerascope:eqversion:2.33

Trust: 1.0

vendor:axismodel:2130 ptz network camerascope:eqversion:2.31

Trust: 1.0

vendor:axismodel:230 mpeg2 video serverscope:eqversion:3.11

Trust: 1.0

vendor:axismodel:2110 network camerascope:eqversion:2.32

Trust: 1.0

vendor:axismodel:2120 network camerascope:eqversion:2.34

Trust: 1.0

vendor:axismodel:2100 network camerascope:eqversion:2.41

Trust: 1.0

vendor:axismodel:2420 network camerascope:eqversion:2.31

Trust: 1.0

vendor:axismodel:2401 video serverscope:eqversion:2.33

Trust: 1.0

vendor:axismodel:2460 network dvrscope:eqversion:3.10

Trust: 1.0

vendor:axismodel:2130 ptz network camerascope:eqversion:2.32

Trust: 1.0

vendor:axismodel:2401 video serverscope:eqversion:3.13

Trust: 1.0

vendor:axismodel:2110 network camerascope:eqversion:2.40

Trust: 1.0

vendor:axismodel:2100 network camerascope:eqversion:2.12

Trust: 1.0

vendor:axismodel:2401 video serverscope:eqversion:2.31

Trust: 1.0

vendor:axismodel:2420 network camerascope:eqversion:2.32

Trust: 1.0

vendor:axismodel:2460 network dvrscope:eqversion:*

Trust: 1.0

vendor:axismodel:2100 network camerascope:eqversion:2.30

Trust: 1.0

vendor:axismodel:storpoint cdscope:eqversion:*

Trust: 1.0

vendor:axismodel:2420 video serverscope:eqversion:2.34

Trust: 1.0

vendor:axismodel:2490 serial serverscope:eqversion:2.11.3

Trust: 1.0

vendor:axismodel:2130 ptz network camerascope:eqversion:2.40

Trust: 1.0

vendor:axismodel:250s video serverscope:eqversion:3.03

Trust: 1.0

vendor:axismodel:2400 video serverscope:eqversion:2.30

Trust: 1.0

vendor:axismodel:2110 network camerascope:eqversion:2.41

Trust: 1.0

vendor:axismodel:2401 video serverscope:eqversion:2.32

Trust: 1.0

vendor:axismodel:2400 video serverscope:eqversion:1.1

Trust: 1.0

vendor:axismodel:2400 video serverscope:eqversion:2.20

Trust: 1.0

vendor:axismodel:2401 video serverscope:eqversion:3.12

Trust: 1.0

vendor:axismodel:2420 network camerascope:eqversion:2.40

Trust: 1.0

vendor:axismodel:2400 video serverscope:eqversion:1.11

Trust: 1.0

vendor:axismodel:2400 video serverscope:eqversion:1.15

Trust: 1.0

vendor:axismodel:2411 video serverscope:eqversion:3.13

Trust: 1.0

vendor:axismodel:2100 network camerascope:eqversion:2.34

Trust: 1.0

vendor:axismodel:2120 network camerascope:eqversion:2.31

Trust: 1.0

vendor:axismodel:2110 network camerascope:eqversion:2.12

Trust: 1.0

vendor:axismodel:2110 network camerascope:eqversion:2.30

Trust: 1.0

vendor:axismodel:communications video serverscope:eqversion:24002.31

Trust: 0.3

vendor:axismodel:communications video serverscope:neversion:2401+3.13

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:24202.32

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:21002.40

Trust: 0.3

vendor:axismodel:communications ptz network camerascope:eqversion:21302.40

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:21002.31

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:21002.34

Trust: 0.3

vendor:axismodel:communications 250s mpeg-2 video serverscope:neversion:3.20

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:24001.02

Trust: 0.3

vendor:axismodel:communications ptz network camerascope:eqversion:21302.31

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:24002.32

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:24001.15

Trust: 0.3

vendor:axismodel:communications video serverscope:neversion:24012.34.1

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:21002.32

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:21002.30

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:24012.32

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:24202.32

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:21202.30

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:24113.12

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:21202.32

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:24002.33

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:21202.31

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:2400+3.12

Trust: 0.3

vendor:axismodel:communications network camerascope:neversion:24202.42

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:21102.32

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:24202.41

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:24002.20

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:2401+3.13

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:24012.20

Trust: 0.3

vendor:axismodel:communications ptz network camerascope:eqversion:21302.34

Trust: 0.3

vendor:axismodel:communications network dvrscope:eqversion:2460

Trust: 0.3

vendor:axismodel:communications video serverscope:neversion:24113.13

Trust: 0.3

vendor:axismodel:communications network camerascope:neversion:21302.42

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:24202.12

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:21202.34

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:24002.30

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:21002.41

Trust: 0.3

vendor:axismodel:communications video serverscope:neversion:2400+3.13

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:24002.34

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:24202.33

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:24012.31

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:24002.0

Trust: 0.3

vendor:axismodel:communications 250s mpeg-2 video serverscope:eqversion:3.10

Trust: 0.3

vendor:axismodel:communications serial serverscope:eqversion:2490

Trust: 0.3

vendor:axismodel:communications ptz network camerascope:eqversion:21302.32

Trust: 0.3

vendor:axismodel:communications mpeg-2 video serverscope:neversion:2303.20

Trust: 0.3

vendor:axismodel:communications 250s video serverscope:eqversion:3.03

Trust: 0.3

vendor:axismodel:communications blade video serverscope:neversion:2401+3.13

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:21002.12

Trust: 0.3

vendor:axismodel:communications network camerascope:neversion:21202.42

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:24001.12

Trust: 0.3

vendor:axismodel:communications network camerascope:neversion:21002.42

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:24011.01

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:2400+3.11

Trust: 0.3

vendor:axismodel:communications video serverscope:neversion:24002.34.1

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:24012.33

Trust: 0.3

vendor:axismodel:communications network dvrscope:eqversion:24603.10

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:21202.12

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:24113.13

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:21202.40

Trust: 0.3

vendor:axismodel:communications network dvrscope:eqversion:24603.11

Trust: 0.3

vendor:axismodel:communications mpeg-2 video server 250sscope: - version: -

Trust: 0.3

vendor:axismodel:communications storpoint cdscope: - version: -

Trust: 0.3

vendor:axismodel:communications serial serverscope:eqversion:24902.11.3

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:24012.34

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:24001.10

Trust: 0.3

vendor:axismodel:communications blade video serverscope:eqversion:2400+3.12

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:21102.41

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:24202.34

Trust: 0.3

vendor:axismodel:communications network camerascope:neversion:21102.42

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:24202.40

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:2401+3.12

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:24001.11

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:24011.15

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:21002.33

Trust: 0.3

vendor:axismodel:communications blade video serverscope:neversion:2400+3.13

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:24202.34

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:24202.31

Trust: 0.3

vendor:axismodel:communications ptz network camerascope:eqversion:21302.30

Trust: 0.3

vendor:axismodel:communications digital video recorderscope:neversion:24603.13

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:24001.01

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:21102.12

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:21102.34

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:21102.30

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:24012.30

Trust: 0.3

vendor:axismodel:communications mpeg-2 video serverscope:eqversion:2303.11

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:21202.41

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:21102.40

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:21102.31

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:24202.30

Trust: 0.3

vendor:axismodel:communications blade video serverscope:eqversion:2401+3.12

Trust: 0.3

sources: BID: 11011 // CNNVD: CNNVD-200412-745 // NVD: CVE-2004-2426

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2004-2426
value: MEDIUM

Trust: 1.0

CNNVD: CNNVD-200412-745
value: MEDIUM

Trust: 0.6

VULHUB: VHN-10854
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2004-2426
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-10854
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-10854 // CNNVD: CNNVD-200412-745 // NVD: CVE-2004-2426

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2004-2426

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200412-745

TYPE

path traversal

Trust: 0.6

sources: CNNVD: CNNVD-200412-745

EXTERNAL IDS

db:BIDid:11011

Trust: 2.0

db:SECTRACKid:1011056

Trust: 1.7

db:SECUNIAid:12353

Trust: 1.7

db:OSVDBid:9122

Trust: 1.7

db:NVDid:CVE-2004-2426

Trust: 1.7

db:CNNVDid:CNNVD-200412-745

Trust: 0.7

db:FULLDISCid:20040831 AXIS NETWORK CAMERA AND VIDEO SERVER SECURITY ADVISORY

Trust: 0.6

db:FULLDISCid:20040822 [POC] NASTY BUG(S) FOUND IN AXIS NETWORK CAMERA/VIDEO SERVERS

Trust: 0.6

db:XFid:17079

Trust: 0.6

db:VULHUBid:VHN-10854

Trust: 0.1

sources: VULHUB: VHN-10854 // BID: 11011 // CNNVD: CNNVD-200412-745 // NVD: CVE-2004-2426

REFERENCES

url:http://www.securityfocus.com/bid/11011

Trust: 1.7

url:http://archives.neohapsis.com/archives/fulldisclosure/2004-08/0948.html

Trust: 1.7

url:http://archives.neohapsis.com/archives/fulldisclosure/2004-08/1282.html

Trust: 1.7

url:http://www.osvdb.org/9122

Trust: 1.7

url:http://securitytracker.com/id?1011056

Trust: 1.7

url:http://secunia.com/advisories/12353

Trust: 1.7

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/17079

Trust: 1.1

url:http://xforce.iss.net/xforce/xfdb/17079

Trust: 0.6

url:http://www.axis.com/products/camera_servers/index.htm

Trust: 0.3

url:/archive/1/372643

Trust: 0.3

url:/archive/1/372630

Trust: 0.3

sources: VULHUB: VHN-10854 // BID: 11011 // CNNVD: CNNVD-200412-745 // NVD: CVE-2004-2426

CREDITS

bashis

Trust: 0.6

sources: CNNVD: CNNVD-200412-745

SOURCES

db:VULHUBid:VHN-10854
db:BIDid:11011
db:CNNVDid:CNNVD-200412-745
db:NVDid:CVE-2004-2426

LAST UPDATE DATE

2024-08-14T14:00:43.965000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-10854date:2017-07-11T00:00:00
db:BIDid:11011date:2007-02-06T20:08:00
db:CNNVDid:CNNVD-200412-745date:2005-10-20T00:00:00
db:NVDid:CVE-2004-2426date:2017-07-11T01:31:53.170

SOURCES RELEASE DATE

db:VULHUBid:VHN-10854date:2004-12-31T00:00:00
db:BIDid:11011date:2004-08-23T00:00:00
db:CNNVDid:CNNVD-200412-745date:2004-12-31T00:00:00
db:NVDid:CVE-2004-2426date:2004-12-31T05:00:00