| Vulnerability Name: | CVE-2007-5213 (CCN-36838) | ||||||||
| Assigned: | 2007-09-27 | ||||||||
| Published: | 2007-09-27 | ||||||||
| Updated: | 2018-10-15 | ||||||||
| Summary: | Multiple cross-site request forgery (CSRF) vulnerabilities in the AXIS 2100 Network Camera 2.02 with firmware 2.43 and earlier allow remote attackers to perform actions as administrators, as demonstrated by (1) an SMTP server change through the conf_SMTP_MailServer1 parameter to ServerManager.srv and (2) a hostname change through the conf_Network_HostName parameter on the Network page. | ||||||||
| CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
| CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C) 7.5 High (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:U/RC:UR)
3.5 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:U/RC:UR)
| ||||||||
| Vulnerability Type: | CWE-352 | ||||||||
| Vulnerability Consequences: | Gain Access | ||||||||
| References: | Source: MITRE Type: CNA CVE-2007-5213 Source: OSVDB Type: UNKNOWN 39490 Source: OSVDB Type: UNKNOWN 39491 Source: SREASON Type: UNKNOWN 3188 Source: CCN Type: Axis Technical Note Reference Document XSS Vulnerabilities and Security Releases for the AXIS 2100/2120 Source: CCN Type: Axis Communications Web site Axis 2100 Source: CCN Type: OSVDB ID: 39490 AXIS 2100 Network Camera Multiple ServerManager.srv conf_SMTP_MailServer1 Parameter CSRF Source: CCN Type: OSVDB ID: 39491 AXIS 2100 Network Camera Multiple Network Page conf_Network_HostName Parameter CSRF Source: CCN Type: ProCheckUp Web site Owning Big Brother: Multiple vulnerabilities on Axis 2100 IP cameras Source: MISC Type: Exploit http://www.procheckup.com/Vulnerability_Axis_2100_research.pdf Source: BUGTRAQ Type: UNKNOWN 20070928 Owning Big Brother: How to Crack into Axis IP cameras Source: BID Type: UNKNOWN 25837 Source: CCN Type: BID-25837 Axis Communications 2100 Network Camera Multiple Input Validation Vulnerabilities Source: XF Type: UNKNOWN axis2100-post-request-csrf(36838) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||