#VU13387 Improper input validation in Axis Communications video cameras - CVE-2018-10664
Published: June 19, 2018
Axis Communications video cameras
Axis Communications
Description
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The weakness exists due to insufficient validation of user-supplied input. A remote attacker can issue an HTTP request to a .cgi script URL, with a PATH_INFO that ends with the .srv extension, crash the httpd process and cause (at least) a black screen for viewers that were already logged to the camera using the web interface with default settings.