Multiple Axis video products could allow an attacker to bypass admin authentication

axis-admin-authentication-bypass (12104) The risk level is classified as HighHigh Risk

Description:

Multiple Axis Communications network video camera and video server devices could allow a remote attacker to bypass authentication and gain unauthorized access to Web-based administration tools. By sending a specially-crafted URL request to the admin.shtml file, a remote attacker can bypass authentication and gain unauthorized access to the administration tools to reset the password and modify configuration files.


Consequences:

Bypass Security

Remedy:

Upgrade to the latest version of firmware, available from the Axis Communications Web site. See References.

References:

  • Axis Communications Web site: Axis Communications - Camera and Video Server Support.
  • Core Security Technologies Advisory CORE-2003-0403: Axis Network Camera HTTP Authentication Bypass.
  • BID-7652: Axis Network Camera HTTP Authentication Bypass Vulnerability
  • CVE-2003-0240: The web-based administration capability for various Axis Network Camera products allows remote attackers to bypass access restrictions and modify configuration via an HTTP request to the admin/admin.shtml containing a leading // (double slash).
  • OSVDB ID: 4804: Axis Network Camera HTTP Authentication Bypass
  • SA8876: Axis Network Camera HTTP Authentication Bypass Vulnerability
  • SECTRACK ID: 1006854: Axis Network Camera Web Interface Authentication Flaw Yields Root Access to Remote Users
  • US-CERT VU#799060: Various Axis products allow unauthorized remote privileged access

Platforms Affected:

  • AXIS 2100 Network Camera 2.30
  • AXIS 2100 Network Camera 2.31
  • AXIS 2100 Network Camera 2.32
  • AXIS 2110 Network Camera 2.30
  • AXIS 2110 Network Camera 2.31
  • AXIS 2110 Network Camera 2.32
  • AXIS 2120 Network Camera 2.30
  • AXIS 2120 Network Camera 2.31
  • AXIS 2120 Network Camera 2.32
  • AXIS 2130 PTZ Network Camera 2.30
  • AXIS 2130 PTZ Network Camera 2.31
  • AXIS 2130 PTZ Network Camera 2.32
  • AXIS 2400 Video Server 2.30
  • AXIS 2400 Video Server 2.31
  • AXIS 2400 Video Server 2.32
  • AXIS 2401 Video Server 2.30
  • AXIS 2401 Video Server 2.31
  • AXIS 2401 Video Server 2.32
  • AXIS 2420 Network Camera 2.30
  • AXIS 2420 Network Camera 2.31
  • AXIS 2420 Network Camera 2.32

Reported:

May 29, 2003

The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

For corrections or additions please email xforce@iss.net

Return to the main page