VYPR

M1033 W Firmware

by Axis

CVEs (9)

  • CVE-2018-10661CriJun 26, 2018
    risk 0.74cvss 9.8epss 0.87

    An issue was discovered in multiple models of Axis IP Cameras. There is a bypass of access control.

  • CVE-2018-10662CriJun 26, 2018
    risk 0.73cvss 9.8epss 0.80

    An issue was discovered in multiple models of Axis IP Cameras. There is an Exposed Insecure Interface.

  • CVE-2018-10660CriJun 26, 2018
    risk 0.73cvss 9.8epss 0.82

    An issue was discovered in multiple models of Axis IP Cameras. There is Shell Command Injection.

  • CVE-2018-10664HigJun 26, 2018
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in the httpd process in multiple models of Axis IP Cameras. There is Memory Corruption.

  • CVE-2018-10663HigJun 26, 2018
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in multiple models of Axis IP Cameras. There is an Incorrect Size Calculation.

  • CVE-2018-10659HigJun 26, 2018
    risk 0.49cvss 7.5epss 0.02

    There was a Memory Corruption issue discovered in multiple models of Axis IP Cameras which allows remote attackers to cause a denial of service (crash) by sending a crafted command which will result in a code path that calls the UND undefined ARM instruction.

  • CVE-2018-10658HigJun 26, 2018
    risk 0.49cvss 7.5epss 0.02

    There was a Memory Corruption issue discovered in multiple models of Axis IP Cameras which causes a denial of service (crash). The crash arises from code inside libdbus-send.so shared object or similar.

  • CVE-2018-9158HigApr 1, 2018
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on AXIS M1033-W (IP camera) Firmware version 5.40.5.1 devices. They don't employ a suitable mechanism to prevent a DoS attack, which leads to a response time delay. An attacker can use the hping3 tool to perform an IPv4 flood attack, and the services are…

  • CVE-2018-9157HigApr 1, 2018
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered on AXIS M1033-W (IP camera) Firmware version 5.40.5.1 devices. The upload web page doesn't verify the file type, and an attacker can upload a webshell by making a fileUpload.shtml request for a custom .shtml file, which is interpreted by the Apache HTTP…