CVE-2018-9157
Last modified
CVE-2018-9157 is a vulnerability of currently unknown severity. An issue was discovered on AXIS M1033-W (IP camera) Firmware version 5.40.5.1 devices. The upload web page doesn't verify the file type, and an attacker can upload a webshell by making a fileUpload.shtml request for a custom .shtml file, which is interpreted by the Apache HTTP Server mod_include module with "<!--#exec cmd=" support. EPSS estimates a 3.22% chance of exploitation in the next 30 days.
Description
An issue was discovered on AXIS M1033-W (IP camera) Firmware version 5.40.5.1 devices. The upload web page doesn't verify the file type, and an attacker can upload a webshell by making a fileUpload.shtml request for a custom .shtml file, which is interpreted by the Apache HTTP Server mod_include module with "<!--#exec cmd=" support. The file needs to include a specific string to meet the internal system architecture. After the webshell upload, an attacker can use the webshell to perform remote code execution such as running a system command (ls, ping, cat /etc/passwd, etc.). NOTE: the vendor reportedly indicates that this is an intended feature or functionality
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Axis | M1033-W Firmware | 5.40.5.1 |
References
- https://www.slideshare.net/secret/pRWQOOe6rN8IybThird Party Advisory
- https://www.slideshare.net/secret/pRWQOOe6rN8IybThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-9157?
How severe is CVE-2018-9157?
How do I fix CVE-2018-9157?
Are you affected by CVE-2018-9157?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
