I'm going through a backlog of CISA KEV CVE's we don't have, and somehow, this got caught in the crossfire.
A triple-exploit chain. auth bypass (1) to exposed dbus interface (2) to command injection (3)
https://www.exploit-db.com/exploits/45100
=> More informations about this toot | More toots from da_667@infosec.exchange
also found this.
https://web.archive.org/web/20200924061118/https://www.vdoo.com/blog/vdoo-discovers-significant-vulnerabilities-in-axis-cameras/
website redirected to new owners, and I think the blog post got lost. Many such cases.
=> More informations about this toot | More toots from da_667@infosec.exchange This content has been proxied by September (ba2dc).Proxy Information
text/gemini