CVE-2004-2426: Medium severity axis 2120 network camera vulnerability
Directory traversal vulnerability in Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to bypass authentication via a .. (dot dot) in an HTTP POST request to ServerManager.srv, then use these privileges to conduct other activities, such as modifying files using editcgi.cgi.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-2426?
CVE-2004-2426 is classified as a medium severity vulnerability that allows remote attackers to bypass authentication.
How do I fix CVE-2004-2426?
To mitigate CVE-2004-2426, users should update their Axis Network Camera or Video Server to versions that are not affected, specifically versions released after 2.40 and 3.12.
What are the affected software versions for CVE-2004-2426?
CVE-2004-2426 affects Axis Network Camera versions 2.40 and earlier, and Video Server versions 3.12 and earlier.
Can CVE-2004-2426 lead to further attacks?
Yes, once the authentication is bypassed due to CVE-2004-2426, attackers can modify files and conduct additional malicious activities.
Is there a workaround for CVE-2004-2426?
A temporary workaround for CVE-2004-2426 is to restrict access to the affected devices from untrusted networks until a firmware update can be applied.