peter bassill · operator
$ cve CVE-2003-0240 JSON

CVE-2003-0240 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 29.5% (pctl 98)

Patch early

A public exploit exists.

Description

The web-based administration capability for various Axis Network Camera products allows remote attackers to bypass access restrictions and modify configuration via an HTTP request to the admin/admin.shtml containing a leading // (double slash).

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS29.52% — more likely to be exploited than 98% of all CVEs
On CISA KEVno
Public exploityes
Published2003-06-09
Last modified2026-06-16

Affected (9)

VendorProduct
axis2100 network camera
axis2110 network camera
axis2120 network camera
axis2130 ptz network camera
axis2400 video server
axis2401 video server
axis2420 network camera
axis2460 network dvr
axis250s video server

Public exploits

SourceTitleDate
exploit-dbAxis Network Camera 2.x - HTTP Authentication Bypass2003-05-27

References

→ the Explorer  ·  watch your stack  ·  NVD