CVE-2018-10659
high-risk
Published 2018-06-26
There was a Memory Corruption issue discovered in multiple models of Axis IP Cameras which allows remote attackers to cause a denial of service (crash) by sending a crafted command which will result in a code path that calls the UND undefined ARM instruction.
Do I need to act?
~
1.2% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.5/10
High
NETWORK
/ LOW complexity
Affected Products (20)
Affected Vendors
References (6)
Vendor Advisory
https://www.axis.com/files/faq/Advisory_ACV-128401.pdf
Vendor Advisory
https://www.axis.com/files/faq/Advisory_ACV-128401.pdf
63
/ 100
high-risk
Severity
26/34 · High
Exploitability
4/34 · Minimal
Exposure
33/34 · Critical