CVE-2000-0144: High severity Axis 700 Network Document Server vulnerability
Axis 700 Network Scanner does not properly restrict access to administrator URLs, which allows users to bypass the password protection via a .. (dot dot) attack.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Configure the device to require authentication for all administrator URLs and enable input/path validation or normalization to prevent directory-traversal sequences (e.g., reject or normalize any '..' path components) so password protection cannot be bypassed.
Axis 700 Network Document Server administrator URL access / path validation = require authentication; reject/normalize paths containing '..' - Configuration
Disable remote web administration or restrict the administrative interface to the local management network or specific trusted IP addresses until a vendor fix is available.
Axis 700 Network Document Server remote administration access = disabled or limited to trusted network - Compensating control
Restrict access to the device's management ports and administrative URLs at network boundaries (firewall/ACL/VLAN) to trusted IP addresses or a management network to prevent untrusted users from reaching administrative endpoints.
- Operational
Audit access logs for attempts to access administrator URLs or evidence of directory-traversal attacks; if unauthorized access is suspected, investigate and rotate administrative credentials and restore affected configurations.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0144?
CVE-2000-0144 is classified as a moderate vulnerability due to its potential to allow unauthorized access to administrator functions.
How do I fix CVE-2000-0144?
To fix CVE-2000-0144, ensure proper access controls and URL restrictions are implemented on the Axis 700 Network Document Server.
What software versions are affected by CVE-2000-0144?
CVE-2000-0144 affects versions 1.0, 1.10, 1.11, 1.12, 1.13, and 1.14 of the Axis 700 Network Document Server.
What exploit methods are used for CVE-2000-0144?
CVE-2000-0144 can be exploited using a directory traversal attack, allowing attackers to access protected resources.
Who is affected by CVE-2000-0144?
Users of the Axis 700 Network Document Server with vulnerable versions may be at risk of unauthorized access to their systems.