#VU13384 Authorization bypass in Axis Communications video cameras


Published: 2020-03-18

Vulnerability identifier: #VU13384

Vulnerability risk: Low

CVSSv3.1: 9.1 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C]

CVE-ID: CVE-2018-10661

CWE-ID: CWE-862

Exploitation vector: Network

Exploit availability: Yes

Vulnerable software:
Axis Communications video cameras
Hardware solutions / Firmware

Vendor: Axis Communications

Description

The vulnerability allows a remote attacker to bypass authorization on the target system.

The weakness exists in mod_authz_axisgroupfile.so: a custom authorization module for Apache httpd that was written by the vendor due to insufficient validation of user-supplied input. A remote attacker can send unauthenticated requests to a world-readable file that are followed by a backslash and end with the .srv extension that are treated by the authorization code as standard requests to the index.html and thus granted access and bypass the web-server’s authorization mechanism.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Axis Communications video cameras: All versions


External links
http://blog.vdoo.com/2018/06/18/vdoo-discovers-significant-vulnerabilities-in-axis-cameras/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability. However, a fully functional exploit for this vulnerability is available.


Latest bulletins with this vulnerability