CVE-2004-2427: Critical severity axis 2120 network camera vulnerability
Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to obtain sensitive information via direct requests to (1) admin/getparam.cgi, (2) admin/systemlog.cgi, (3) admin/serverreport.cgi, and (4) admin/paramlist.cgi, modify system information via (5) setparam.cgi and (6) factorydefault.cgi, or (7) cause a denial of service (reboot) via restart.cgi.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What are the risks associated with CVE-2004-2427?
CVE-2004-2427 allows unauthorized remote access to sensitive information on affected Axis Network Cameras and Video Servers, posing a significant data security risk.
How can I prevent exploitation of CVE-2004-2427?
To prevent exploitation of CVE-2004-2427, ensure that your Axis Network Camera or Video Server firmware is updated to the latest version.
Which devices are affected by CVE-2004-2427?
CVE-2004-2427 affects various versions of the Axis 2100 and 2400 Network Cameras and Video Servers, specifically those running versions 2.40 and earlier or 3.12 and earlier.
What is the vulnerability type of CVE-2004-2427?
CVE-2004-2427 is classified as an information disclosure vulnerability.
What actions should I take if my device is affected by CVE-2004-2427?
If your device is affected by CVE-2004-2427, immediately update your firmware and review device access controls to restrict unauthorized access.