cbcvebase.
CVE-2018-10661
published 2018-06-26

CVE-2018-10661: An issue was discovered in multiple models of Axis IP Cameras. There is a bypass of access control.

critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
ITWEXPLOIT
Exploited in the wild
An issue was discovered in multiple models of Axis IP Cameras. There is a bypass of access control.

Affected

390 ranges· showing 25
VendorProductVersion rangeFixed in
axisa1001_firmware< 1.65.11.65.1
axisa8004-v_firmware< 1.65.21.65.2
axisa8105-e_firmware< 1.65.21.65.2
axisa9161_firmware< 1.65.01.65.0
axisa9188-v_firmware< 1.65.01.65.0
axisa9188_firmware< 1.65.01.65.0
axisc1004-e_firmware< 1.81.040.11.81.040.1
axisc2005_firmware< 1.81.040.11.81.040.1
axisc3003-e_firmware< 1.81.040.11.81.040.1
axisc8033_firmware< 1.81.040.11.81.040.1
axiscompanion_bullet_le_firmware< 8.20.18.20.1
axiscompanion_c360_firmware< 7.15.2.37.15.2.3
axiscompanion_cube_l_firmware< 8.20.18.20.1
axiscompanion_cube_lw_firmware< 8.20.18.20.1
axiscompanion_dome_v_firmware< 8.20.18.20.1
axiscompanion_dome_wv_firmware< 8.20.18.20.1
axiscompanion_eye_l_firmware< 8.20.18.20.1
axiscompanion_eye_lve_firmware< 8.20.18.20.1
axiscompanion_recorder_4ch_firmware< 1.20.11.20.1
axiscompanion_recorder_8ch_firmware< 1.20.11.20.1
axisd201-s_xpt_q6055_firmware< 6.50.2.36.50.2.3
axisd2050-ve_firmware< 7.35.4.27.35.4.2
axisf34_main_unit_firmware< 6.50.2.36.50.2.3
axisf41_main_unit_firmware< 6.50.2.36.50.2.3
axisf44_dual_audio_input_firmware< 6.50.2.36.50.2.3

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL