HTTP: AXIS Communications Camera Control (AxisCamControl.ocx) Unsafe ActiveX Control

This signature detects attempts to exploit a known vulnerability in AXIS Communications Camera Control ActiveX control, AxisCamControl.ocx. An attacker can create a malicious Web site with Web pages containing dangerous ActiveX controls, which if accessed by a victim, allows the attacker to gain control of the victim's client browser.

Extended Description

AXIS Camera Control ActiveX control is prone to a buffer-overflow vulnerability because the application fails to adequately check boundaries on user-supplied input. An attacker can exploit this issue to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions. Axis Camera Control 2.40.0.0 is vulnerable; other versions may also be vulnerable.

Affected Products

Axis_communications camera_control

Short Name
HTTP:STC:ACTIVEX:AXIS-CAMERA
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
(AxisCamControl.ocx) AXIS ActiveX CVE-2008-5260 Camera Communications Control Unsafe bid:33408
Release Date
01/30/2009
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3725
False Positive
Unknown
Vendors

Axis_communications

CVSS Score

9.3

Found a potential security threat?