CVE-2017-12413: XSS
Published Aug 4, 2017
·Updated
AXIS 2100 devices 2.43 have XSS via the URI, possibly related to admin/admin.shtml.
Affected Software
2 affected components
Axis 2100 Network Camera Firmware=2.43
Axis 2100 Network Camera
Event History
Aug 4, 2017
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-12413?
CVE-2017-12413 has a medium severity rating due to its Cross-Site Scripting (XSS) vulnerability affecting AXIS 2100 devices.
2
How do I fix CVE-2017-12413?
To fix CVE-2017-12413, update your AXIS 2100 Network Camera firmware to a version later than 2.43.
3
What causes the CVE-2017-12413 vulnerability?
CVE-2017-12413 is caused by insufficient validation of user-supplied input in the URI, allowing XSS attacks.
4
What devices are affected by CVE-2017-12413?
CVE-2017-12413 specifically affects AXIS 2100 Network Camera running firmware version 2.43.
5
Is the AXIS 2100 Network Camera firmware prior to version 2.43 safe from CVE-2017-12413?
No, any firmware version prior to 2.43 is vulnerable to CVE-2017-12413 and should be updated.