CVE-2018-10658
UnknownEPSS 1.52%
Last modified
CVE-2018-10658 is a vulnerability of currently unknown severity. There was a Memory Corruption issue discovered in multiple models of Axis IP Cameras which causes a denial of service (crash). The crash arises from code inside libdbus-send.so shared object or similar.. EPSS estimates a 1.52% chance of exploitation in the next 30 days.
Description
There was a Memory Corruption issue discovered in multiple models of Axis IP Cameras which causes a denial of service (crash). The crash arises from code inside libdbus-send.so shared object or similar.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Axis | A1001 Firmware | < 1.65.1 |
| Axis | A8004-V Firmware | < 1.65.2 |
| Axis | A8105-E Firmware | < 1.65.2 |
| Axis | A9161 Firmware | < 1.65.0 |
| Axis | A9188 Firmware | < 1.65.0 |
| Axis | A9188-V Firmware | < 1.65.0 |
| Axis | C1004-E Firmware | < 1.81.040.1 |
| Axis | C2005 Firmware | < 1.81.040.1 |
| Axis | C3003-E Firmware | < 1.81.040.1 |
| Axis | C8033 Firmware | < 1.81.040.1 |
| Axis | Companion Bullet Le Firmware | < 8.20.1 |
| Axis | Companion C360 Firmware | < 7.15.2.3 |
| Axis | Companion Cube L Firmware | < 8.20.1 |
| Axis | Companion Cube Lw Firmware | < 8.20.1 |
| Axis | Companion Dome V Firmware | < 8.20.1 |
| Axis | Companion Dome Wv Firmware | < 8.20.1 |
| Axis | Companion Eye L Firmware | < 8.20.1 |
| Axis | Companion Eye Lve Firmware | < 8.20.1 |
| Axis | Companion Recorder 4ch Firmware | < 1.20.1 |
| Axis | Companion Recorder 8ch Firmware | < 1.20.1 |
| Axis | D2050-Ve Firmware | < 7.35.4.2 |
| Axis | F34 Main Unit Firmware | < 6.50.2.3 |
| Axis | F41 Main Unit Firmware | < 6.50.2.3 |
| Axis | F44 Dual Audio Input Firmware | < 6.50.2.3 |
| Axis | F44 Main Unit Firmware | < 6.50.2.3 |
| Axis | Fa54 Main Unit Firmware | < 6.55.4.5 |
| Axis | M1004-W Firmware | < 5.51.5 |
| Axis | M1013 Firmware | < 5.51.5 |
| Axis | M1014 Firmware | < 5.51.5 |
| Axis | M1025 Firmware | < 5.51.5 |
| Axis | M1033-W Firmware | < 5.51.5 |
| Axis | M1034-W Firmware | < 5.51.5 |
| Axis | M1045-Lw Firmware | < 8.20.1 |
| Axis | M1054 Firmware | < 5.51.5 |
| Axis | M1065-L Firmware | < 8.20.1 |
| Axis | M1065-Lw Firmware | < 8.20.1 |
| Axis | M1103 Firmware | < 5.51.5 |
| Axis | M1104 Firmware | < 5.51.5 |
| Axis | M1113 Firmware | < 5.51.5 |
| Axis | M1113-E Firmware | < 5.51.5 |
| Axis | M1114 Firmware | < 5.51.5 |
| Axis | M1114-E Firmware | < 5.51.5 |
| Axis | M1124 Firmware | < 6.50.2.3 |
| Axis | M1124-E Firmware | < 6.50.2.3 |
| Axis | M1125 Firmware | < 6.50.2.3 |
| Axis | M1125-E Firmware | < 6.50.2.3 |
| Axis | M1143-L Firmware | < 5.60.1.10 |
| Axis | M1144-L Firmware | < 5.60.1.10 |
| Axis | M1145 Firmware | < 6.50.2.3 |
| Axis | M1145-L Firmware | < 6.50.2.3 |
Showing 50 of 390 affected configurations. See NVD for the full list.
References
- https://blog.vdoo.com/2018/06/18/vdoo-discovers-significant-vulnerabilities-in-axis-cameras/Exploit, Third Party Advisory
- https://www.axis.com/files/faq/Advisory_ACV-128401.pdfVendor Advisory
- https://blog.vdoo.com/2018/06/18/vdoo-discovers-significant-vulnerabilities-in-axis-cameras/Exploit, Third Party Advisory
- https://www.axis.com/files/faq/Advisory_ACV-128401.pdfVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-10658?
There was a Memory Corruption issue discovered in multiple models of Axis IP Cameras which causes a denial of service (crash). The crash arises from code inside libdbus-send.so shared object or similar.
How severe is CVE-2018-10658?
Severity scoring for CVE-2018-10658 is pending analysis. The EPSS model estimates a 1.52% probability of exploitation in the next 30 days.
How do I fix CVE-2018-10658?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
Are you affected by CVE-2018-10658?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
