CVE-2017-20049

A vulnerability, which was classified as critical, was found in AXIS P1204, P3225, P3367, M3045, M3005 and M3007. This affects an unknown part of the component CGI Script. The manipulation leads to improper privilege management. It is possible to initiate the attack remotely. It is recommended to upgrade the affected component.
References
Link Resource
http://seclists.org/fulldisclosure/2017/Mar/41 Exploit Mailing List Third Party Advisory
https://vuldb.com/?id.98913 Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:axis:p1204_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:axis:p1204:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:axis:p3225_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:axis:p3225:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:axis:p3367_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:axis:p3367:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:axis:m3045_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:axis:m3045:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:axis:m3005_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:axis:m3005:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:axis:m3007_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:axis:m3007:-:*:*:*:*:*:*:*

Information

Published : 2022-06-15 18:15

Updated : 2022-06-24 19:11


NVD link : CVE-2017-20049

Mitre link : CVE-2017-20049


JSON object : View

Products Affected

axis

  • m3005_firmware
  • p1204_firmware
  • p3367_firmware
  • m3045
  • m3005
  • p1204
  • p3225
  • p3367
  • m3045_firmware
  • m3007_firmware
  • p3225_firmware
  • m3007
CWE
CWE-269

Improper Privilege Management