RULE(RULE ID:324274)

Rule General Information
Release Date: 2020-01-21
Rule Name: Axis Network Camera Authorization Bypass Vulnerability (CVE-2018-10661)
Severity:
CVE ID:
Rule Protection Details
Description: An issue was discovered in multiple models of Axis IP Cameras. Attackers can use this vulnerability to bypass the authorization mechanism of the web-server by sending unauthenticated requests.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Network Device
Reference: ExploitDB:45100
https://blog.vdoo.com/2018/06/18/vdoo-discovers-significant-vulnerabilities-in-axis-cameras/
https://www.axis.com/files/faq/Advisory_ACV-128401.pdf
https://www.axis.com/files/sales/ACV-128401_Affected_Product_List.pdf
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://www.axis.com/files/faq/Advisory_ACV-128401.pdf