CVE-2017-20049

A vulnerability, was found in legacy Axis devices such as P3225 and M3005. This affects an unknown part of the component CGI Script. The manipulation leads to improper privilege management. It is possible to initiate the attack remotely.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:axis:p1204_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:axis:p1204:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:axis:p3225_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:axis:p3225:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:axis:p3367_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:axis:p3367:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:axis:m3045_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:axis:m3045:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:axis:m3005_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:axis:m3005:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:axis:m3007_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:axis:m3007:-:*:*:*:*:*:*:*

History

21 Nov 2024, 03:22

Type Values Removed Values Added
References () https://www.axis.com/dam/public/df/f3/dd/cve-2017-20049-en-US-376956.pdf - () https://www.axis.com/dam/public/df/f3/dd/cve-2017-20049-en-US-376956.pdf -

07 Nov 2023, 02:43

Type Values Removed Values Added
References (MISC) https://www.axis.com/dam/public/df/f3/dd/cve-2017-20049-en-US-376956.pdf - () https://www.axis.com/dam/public/df/f3/dd/cve-2017-20049-en-US-376956.pdf -

Information

Published : 2022-06-15 18:15

Updated : 2024-11-21 03:22


NVD link : CVE-2017-20049

Mitre link : CVE-2017-20049

CVE.ORG link : CVE-2017-20049


JSON object : View

Products Affected

axis

  • p3225_firmware
  • m3045_firmware
  • p1204_firmware
  • m3045
  • m3007
  • m3005
  • p3225
  • p3367
  • m3005_firmware
  • p1204
  • m3007_firmware
  • p3367_firmware
CWE
CWE-269

Improper Privilege Management