CVE-2004-2425

UnknownEPSS 13.53%

Last modified

CVE-2004-2425 is a vulnerability of currently unknown severity. Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to execute arbitrary commands via accent (`) and possibly other shell metacharacters in the query string to virtualinput.cgi.. EPSS estimates a 13.53% chance of exploitation in the next 30 days.

Description

Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to execute arbitrary commands via accent (`) and possibly other shell metacharacters in the query string to virtualinput.cgi.

Metrics

EPSS Probability
13.53%

96.0th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
Axis2100 Network Camera2.12
Axis2100 Network Camera2.30
Axis2100 Network Camera2.31
Axis2100 Network Camera2.32
Axis2100 Network Camera2.33
Axis2100 Network Camera2.34
Axis2100 Network Camera2.40
Axis2100 Network Camera2.41
Axis2110 Network Camera2.12
Axis2110 Network Camera2.30
Axis2110 Network Camera2.31
Axis2110 Network Camera2.32
Axis2110 Network Camera2.34
Axis2110 Network Camera2.40
Axis2110 Network Camera2.41
Axis2120 Network Camera2.12
Axis2120 Network Camera2.30
Axis2120 Network Camera2.31
Axis2120 Network Camera2.32
Axis2120 Network Camera2.34
Axis2120 Network Camera2.40
Axis2120 Network Camera2.41
Axis2130 Ptz Network Camera2.30
Axis2130 Ptz Network Camera2.31
Axis2130 Ptz Network Camera2.32
Axis2130 Ptz Network Camera2.34
Axis2130 Ptz Network Camera2.40
Axis230 Mpeg2 Video Server3.11
Axis2400 Video Server1.1
Axis2400 Video Server1.2
Axis2400 Video Server1.10
Axis2400 Video Server1.11
Axis2400 Video Server1.12
Axis2400 Video Server1.15
Axis2400 Video Server2.0
Axis2400 Video Server2.20
Axis2400 Video Server2.30
Axis2400 Video Server2.31
Axis2400 Video Server2.32
Axis2400 Video Server2.33
Axis2400 Video Server2.34
Axis2400 Video Server3.11
Axis2400 Video Server3.12
Axis2401 Video Server1.0_1
Axis2401 Video Server1.15
Axis2401 Video Server2.20
Axis2401 Video Server2.30
Axis2401 Video Server2.31
Axis2401 Video Server2.32
Axis2401 Video Server2.33

Showing 50 of 74 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2004-2425?
Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to execute arbitrary commands via accent (`) and possibly other shell metacharacters in the query string to virtualinput.cgi.
How severe is CVE-2004-2425?
Severity scoring for CVE-2004-2425 is pending analysis. The EPSS model estimates a 13.53% probability of exploitation in the next 30 days.
How do I fix CVE-2004-2425?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2004-2425?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST