CVE-2003-0240

UnknownEPSS 29.52%

Last modified

CVE-2003-0240 is a vulnerability of currently unknown severity. The web-based administration capability for various Axis Network Camera products allows remote attackers to bypass access restrictions and modify configuration via an HTTP request to the admin/admin.shtml containing a leading // (double slash).. EPSS estimates a 29.52% chance of exploitation in the next 30 days.

Description

The web-based administration capability for various Axis Network Camera products allows remote attackers to bypass access restrictions and modify configuration via an HTTP request to the admin/admin.shtml containing a leading // (double slash).

Metrics

EPSS Probability
29.52%

98.0th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
Axis2100 Network Camera<= 2.32
Axis2110 Network Camera<= 2.32
Axis2120 Network Camera<= 2.32
Axis2130 Ptz Network Camera<= 2.32
Axis2400 Video Server<= 2.32
Axis2401 Video Server<= 2.32
Axis2420 Network Camera<= 2.32
Axis2460 Network Dvr<= 3.00
Axis250s Video Server<= 3.02

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2003-0240?
The web-based administration capability for various Axis Network Camera products allows remote attackers to bypass access restrictions and modify configuration via an HTTP request to the admin/admin.shtml containing a leading // (double slash).
How severe is CVE-2003-0240?
Severity scoring for CVE-2003-0240 is pending analysis. The EPSS model estimates a 29.52% probability of exploitation in the next 30 days.
How do I fix CVE-2003-0240?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2003-0240?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST