CVE-2018-10659
published 2018-06-26CVE-2018-10659: There was a Memory Corruption issue discovered in multiple models of Axis IP Cameras which allows remote attackers to cause a denial of service (crash) by…
PriorityP434high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
1.79%
76.0th percentile
There was a Memory Corruption issue discovered in multiple models of Axis IP Cameras which allows remote attackers to cause a denial of service (crash) by sending a crafted command which will result in a code path that calls the UND undefined ARM instruction.
Affected
390 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| axis | a1001_firmware | < 1.65.1 | 1.65.1 |
| axis | a8004-v_firmware | < 1.65.2 | 1.65.2 |
| axis | a8105-e_firmware | < 1.65.2 | 1.65.2 |
| axis | a9161_firmware | < 1.65.0 | 1.65.0 |
| axis | a9188-v_firmware | < 1.65.0 | 1.65.0 |
| axis | a9188_firmware | < 1.65.0 | 1.65.0 |
| axis | c1004-e_firmware | < 1.81.040.1 | 1.81.040.1 |
| axis | c2005_firmware | < 1.81.040.1 | 1.81.040.1 |
| axis | c3003-e_firmware | < 1.81.040.1 | 1.81.040.1 |
| axis | c8033_firmware | < 1.81.040.1 | 1.81.040.1 |
| axis | companion_bullet_le_firmware | < 8.20.1 | 8.20.1 |
| axis | companion_c360_firmware | < 7.15.2.3 | 7.15.2.3 |
| axis | companion_cube_l_firmware | < 8.20.1 | 8.20.1 |
| axis | companion_cube_lw_firmware | < 8.20.1 | 8.20.1 |
| axis | companion_dome_v_firmware | < 8.20.1 | 8.20.1 |
| axis | companion_dome_wv_firmware | < 8.20.1 | 8.20.1 |
| axis | companion_eye_l_firmware | < 8.20.1 | 8.20.1 |
| axis | companion_eye_lve_firmware | < 8.20.1 | 8.20.1 |
| axis | companion_recorder_4ch_firmware | < 1.20.1 | 1.20.1 |
| axis | companion_recorder_8ch_firmware | < 1.20.1 | 1.20.1 |
| axis | d201-s_xpt_q6055_firmware | < 6.50.2.3 | 6.50.2.3 |
| axis | d2050-ve_firmware | < 7.35.4.2 | 7.35.4.2 |
| axis | f34_main_unit_firmware | < 6.50.2.3 | 6.50.2.3 |
| axis | f41_main_unit_firmware | < 6.50.2.3 | 6.50.2.3 |
| axis | f44_dual_audio_input_firmware | < 6.50.2.3 | 6.50.2.3 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://blog.vdoo.com/2018/06/18/vdoo-discovers-significant-vulnerabilities-in-axis-cameras/https://www.axis.com/files/faq/Advisory_ACV-128401.pdfhttps://www.axis.com/files/sales/ACV-128401_Affected_Product_List.pdfhttps://blog.vdoo.com/2018/06/18/vdoo-discovers-significant-vulnerabilities-in-axis-cameras/https://www.axis.com/files/faq/Advisory_ACV-128401.pdfhttps://www.axis.com/files/sales/ACV-128401_Affected_Product_List.pdf
2018-06-26
Published