9
CVSSv2

CVE-2015-8257

Published: 02/05/2017 Updated: 16/05/2017
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 905
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

The devtools.sh script in AXIS network cameras allows remote authenticated users to execute arbitrary commands via shell metacharacters in the app parameter to (1) app_license.shtml, (2) app_license_custom.shtml, (3) app_index.shtml, or (4) app_params.shtml.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

axis network_camera_firmware -

Exploits

_ _ _ _ _ _ _ _ _ _ / \ / \ / \ / \ / \ / \ / \ / \ / \ / \ ( 0 | R | W | 3 | L | L | L | 4 | 8 | 5 ) \_/ \_/ \_/ \_/ \_/ \_/ \_/ \_/ \_/ \_/ wwworwelllabscom security advisory olsa-2015-8257 PGP: 79A6CCC0 * Advisory Information ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ ...
Multiple products from AXIS suffer from a remote command execution vulnerability ...