Subscriber Discussion

Axis Vulnerabilities Reported. CVE-2018-10658 To 10664.

UI
Undisclosed Integrator #1
Jun 18, 2018

Does anyone have additional details about this? I didn't catch any emails and I was wondering if others had been notified.

Vendor Patches Seven Vulnerabilities Across 392 Camera Models

Axis - ACV-128401 Affected Product List

(1)
Avatar
Sean Patton
Jun 18, 2018

UI1,

Thanks for posting this, here is the link to the post from the company (VDOO) that outlines the vulnerability: VDOO Discovers Significant Vulnerabilities in Axis Cameras

We are looking to the vulnerability and were already in discussions with VDOO for an official post last week.

VDOO is a startup that has received $13 million in funding and is building a cybersecurity firmware service for IoT devices like IP Cameras.

A quick look at the vulnerability post, it involves running 3 different vulnerabilities cracks in a specific sequence, in their words:

We will be putting a full report together on the vulnerability and VDOO.

(3)
Avatar
Sean Patton
Jun 20, 2018

Thanks again UI1,

We have posted our report on these vulnerabilities, and the company who disclosed them: Cybersecurity Startup VDOO Disclosing 10 Manufacturer Vulnerabilities Starting With Axis And Foscam

New discussion

Ask questions and get answers to your physical security questions from IPVM team members and fellow subscribers.

Newest discussions