CVE-2018-10664
UnknownEPSS 1.52%
Last modified
CVE-2018-10664 is a vulnerability of currently unknown severity. An issue was discovered in the httpd process in multiple models of Axis IP Cameras. There is Memory Corruption.. EPSS estimates a 1.52% chance of exploitation in the next 30 days.
Description
An issue was discovered in the httpd process in multiple models of Axis IP Cameras. There is Memory Corruption.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Axis | A1001 Firmware | < 1.65.1 |
| Axis | A8004-V Firmware | < 1.65.2 |
| Axis | A8105-E Firmware | < 1.65.2 |
| Axis | A9161 Firmware | < 1.65.0 |
| Axis | A9188 Firmware | < 1.65.0 |
| Axis | A9188-V Firmware | < 1.65.0 |
| Axis | C1004-E Firmware | < 1.81.040.1 |
| Axis | C2005 Firmware | < 1.81.040.1 |
| Axis | C3003-E Firmware | < 1.81.040.1 |
| Axis | C8033 Firmware | < 1.81.040.1 |
| Axis | Companion Bullet Le Firmware | < 8.20.1 |
| Axis | Companion C360 Firmware | < 7.15.2.3 |
| Axis | Companion Cube L Firmware | < 8.20.1 |
| Axis | Companion Cube Lw Firmware | < 8.20.1 |
| Axis | Companion Dome V Firmware | < 8.20.1 |
| Axis | Companion Dome Wv Firmware | < 8.20.1 |
| Axis | Companion Eye L Firmware | < 8.20.1 |
| Axis | Companion Eye Lve Firmware | < 8.20.1 |
| Axis | Companion Recorder 4ch Firmware | < 1.20.1 |
| Axis | Companion Recorder 8ch Firmware | < 1.20.1 |
| Axis | D2050-Ve Firmware | < 7.35.4.2 |
| Axis | F34 Main Unit Firmware | < 6.50.2.3 |
| Axis | F41 Main Unit Firmware | < 6.50.2.3 |
| Axis | F44 Dual Audio Input Firmware | < 6.50.2.3 |
| Axis | F44 Main Unit Firmware | < 6.50.2.3 |
| Axis | Fa54 Main Unit Firmware | < 6.55.4.5 |
| Axis | M1004-W Firmware | < 5.51.5 |
| Axis | M1013 Firmware | < 5.51.5 |
| Axis | M1014 Firmware | < 5.51.5 |
| Axis | M1025 Firmware | < 5.51.5 |
| Axis | M1033-W Firmware | < 5.51.5 |
| Axis | M1034-W Firmware | < 5.51.5 |
| Axis | M1045-Lw Firmware | < 8.20.1 |
| Axis | M1054 Firmware | < 5.51.5 |
| Axis | M1065-L Firmware | < 8.20.1 |
| Axis | M1065-Lw Firmware | < 8.20.1 |
| Axis | M1103 Firmware | < 5.51.5 |
| Axis | M1104 Firmware | < 5.51.5 |
| Axis | M1113 Firmware | < 5.51.5 |
| Axis | M1113-E Firmware | < 5.51.5 |
| Axis | M1114 Firmware | < 5.51.5 |
| Axis | M1114-E Firmware | < 5.51.5 |
| Axis | M1124 Firmware | < 6.50.2.3 |
| Axis | M1124-E Firmware | < 6.50.2.3 |
| Axis | M1125 Firmware | < 6.50.2.3 |
| Axis | M1125-E Firmware | < 6.50.2.3 |
| Axis | M1143-L Firmware | < 5.60.1.10 |
| Axis | M1144-L Firmware | < 5.60.1.10 |
| Axis | M1145 Firmware | < 6.50.2.3 |
| Axis | M1145-L Firmware | < 6.50.2.3 |
Showing 50 of 390 affected configurations. See NVD for the full list.
References
- https://blog.vdoo.com/2018/06/18/vdoo-discovers-significant-vulnerabilities-in-axis-cameras/Exploit, Third Party Advisory
- https://www.axis.com/files/faq/Advisory_ACV-128401.pdfVendor Advisory
- https://blog.vdoo.com/2018/06/18/vdoo-discovers-significant-vulnerabilities-in-axis-cameras/Exploit, Third Party Advisory
- https://www.axis.com/files/faq/Advisory_ACV-128401.pdfVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-10664?
An issue was discovered in the httpd process in multiple models of Axis IP Cameras. There is Memory Corruption.
How severe is CVE-2018-10664?
Severity scoring for CVE-2018-10664 is pending analysis. The EPSS model estimates a 1.52% probability of exploitation in the next 30 days.
How do I fix CVE-2018-10664?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-10659There was a Memory Corruption issue discovered in multiple m…
- CVE-2018-1066The Linux kernel before version 4.11 is vulnerable to a NULL…
- CVE-2018-10660An issue was discovered in multiple models of Axis IP Camera…
- CVE-2018-10661An issue was discovered in multiple models of Axis IP Camera…
- CVE-2018-10662An issue was discovered in multiple models of Axis IP Camera…
- CVE-2018-10663An issue was discovered in multiple models of Axis IP Camera…
- CVE-2018-10665ILIAS 5.3.4 has XSS through unsanitized output of PHP_SELF, …
- CVE-2018-10666The Owned smart contract implementation for Aurora IDEX Memb…
- CVE-2018-1067In Undertow before versions 7.1.2.CR1, 7.1.2.GA it was found…6.1
- CVE-2018-10675The do_get_mempolicy function in mm/mempolicy.c in the Linux…7.8
- CVE-2018-10676CeNova, Night OWL, Novo, Pulnix, QSee, Securus, and TBK Visi…
- CVE-2018-10677The DecodeGifImg function in ngiflib.c in MiniUPnP ngiflib 0…
Are you affected by CVE-2018-10664?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
