First published: Tue May 02 2017(Updated: )
The devtools.sh script in AXIS network cameras allows remote authenticated users to execute arbitrary commands via shell metacharacters in the app parameter to (1) app_license.shtml, (2) app_license_custom.shtml, (3) app_index.shtml, or (4) app_params.shtml.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Axis Network Camera Firmware | ||
Axis Cannon Network Camera | ||
Axis Explosion-protected Camera | ||
Axis Fixed Box Camera | ||
Axis Fixed Bullet Camera | ||
Axis Fixed Dome Camera | ||
Axis Modular Camera | ||
Axis Onboard Camera | ||
Axis Panoramic Camera | ||
Axis Ptz Camera | ||
Axis Thermal Camera |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8257 is classified as a critical vulnerability due to the potential for remote authenticated users to execute arbitrary commands.
Fixing CVE-2015-8257 involves updating the AXIS network camera firmware to the latest version that addresses this vulnerability.
CVE-2015-8257 affects specific AXIS network camera firmware versions that allow command execution via the devtools.sh script.
CVE-2015-8257 is an authenticated remote command execution vulnerability.
The potential consequences of CVE-2015-8257 include unauthorized access and control over affected AXIS network cameras.