Web server vulnerability in Axis Network Cameras, Video Servers and Network Digital Video Recorders
26 Dec. 2002
Summary
A potential stack buffer overflow has been found in the authentication code of the modified version of Boa used in some of the embedded Linux based Axis products, which may result in DoS attacks, or in a potential system compromise.
Affected products:
* Axis 2100/2110/2120/2420 Network Camera - Firmware Release 2.33 and below
* Axis 2130 PTZ Network Camera - Firmware Release 2.32
* Axis 2400/2401 Video Server - Firmware Release 2.33 and below
* Axis 2460 Network DVR - Firmware Release 3.00
* Axis 2490 Serial Server - Firmware Release 2.10
* Axis 250S MPEG-2 Video Server - Firmware Release 3.01
Note: this vulnerability is not present in the official boa distribution available from http://www.boa.org/.
Solution:
The part of the authentication code where the buffer overflow may arise has been corrected and is included in new firmware releases for all affected products.