Axis Network Camera and Video Server contains a flaw that may allow a remote attacker to modify system parameters. The issue is due to the setparam.cgi script not requiring authentication for remote users. This may allow an attacker to load the script and change system parameters that control the devices.
Classification
Location:
Remote / Network Access
Attack Type:
Input Manipulation,
Misconfiguration
Impact:
Loss of Integrity
Exploit:
Exploit Public
OSVDB:
Web Related
Solution
Upgrade to firmware version 2.42 or higher, as it has been reported to fix this vulnerability. It is also possible to correct the flaw by implementing the following workaround: restrict remote access to administrative interface scripts.