CVE-2000-0191: Critical severity axis storpoint cd vulnerability
Axis StorPoint CD allows remote attackers to access administrator URLs without authentication via a .. (dot dot) attack.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict access to the Axis StorPoint CD administrative web interface to trusted management IPs/networks using firewall rules, ACLs, or network segmentation (deny access from untrusted networks and the Internet).
- Compensating control
If possible, block HTTP/HTTPS access to the device from untrusted networks (egress/ingress filtering) or place the device behind a VPN that only authorized administrators can use.
- Operational
Rotate all administrative credentials and any sensitive credentials or keys stored on the device; review administrative and system logs for signs of unauthorized access or configuration changes and remediate any discovered compromise.
- Operational
Monitor the vendor (Axis) for an official security patch or advisory for Axis StorPoint CD and apply the vendor-supplied fix as soon as it is available.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0191?
CVE-2000-0191 is classified as a critical vulnerability due to its potential for unauthorized access to administrator functionality.
How do I fix CVE-2000-0191?
You can fix CVE-2000-0191 by applying the latest security patches provided by Axis for the StorPoint CD software.
What types of attacks are possible with CVE-2000-0191?
CVE-2000-0191 allows remote attackers to exploit directory traversal vulnerabilities to access sensitive administrator URLs.
Is CVE-2000-0191 still a relevant vulnerability?
Yes, CVE-2000-0191 remains relevant as older versions of Axis StorPoint CD that are unpatched are still vulnerable.
What software versions are affected by CVE-2000-0191?
CVE-2000-0191 affects all versions of Axis StorPoint CD that do not have the security updates installed.