CVE-2003-0240: Critical severity Axis 2100 Network Camera vulnerability
The web-based administration capability for various Axis Network Camera products allows remote attackers to bypass access restrictions and modify configuration via an HTTP request to the admin/admin.shtml containing a leading // (double slash).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable the web-based administration (HTTP management interface) on the listed Axis devices to prevent access-control bypass via requests to admin/admin.shtml containing a leading //.
Axis Network Camera web-based administration (admin/admin.shtml) - affected models: AXIS 2420-IR Network Camera, AXIS Video Server, Axis 2100 Network Camera Firmware, Axis 2110 Network Camera, Axis 2120 Network Camera, Axis 2460 Network DVR, Axis PTZ Camera web_admin_access = disabled - Compensating control
Restrict network access to the HTTP administration interface (/admin/admin.shtml) on the affected Axis devices (AXIS 2420-IR, AXIS Video Server, Axis 2100, Axis 2110, Axis 2120, Axis 2460 Network DVR, Axis PTZ Camera) by applying firewall/ACL rules or network segmentation: allow only trusted management IP addresses or a management VLAN and block access from untrusted networks and the Internet.
Event History
Frequently Asked Questions
What is the severity of CVE-2003-0240?
CVE-2003-0240 is a high-severity vulnerability that allows unauthorized remote access to configuration settings of affected Axis Network Camera products.
How do I fix CVE-2003-0240?
To mitigate CVE-2003-0240, it is recommended to update the firmware of the affected Axis Network Camera products to the latest version that addresses this vulnerability.
Which products are affected by CVE-2003-0240?
CVE-2003-0240 affects Axis 2100, 2110, 2120, 2130 PTZ Network Cameras, 2400, 2401 Video Servers, 2420-IR Network Camera, and 2460 Network DVR, among others, all with firmware versions up to 2.32.
What is the attack vector for CVE-2003-0240?
The attack vector for CVE-2003-0240 is through crafted HTTP requests that exploit the web-based administration interface of affected devices.
What is the potential impact of exploiting CVE-2003-0240?
Exploitation of CVE-2003-0240 allows an attacker to bypass security restrictions and potentially alter device configurations, leading to unauthorized access and control.