ID

VAR-200709-0162


CVE

CVE-2007-4928


TITLE

AXIS Vulnerability in camera where important information is obtained

Trust: 0.8

sources: JVNDB: JVNDB-2007-002641

DESCRIPTION

The AXIS 207W camera stores a WEP or WPA key in cleartext in the configuration file, which might allow local users to obtain sensitive information. AXIS The camera is in clear text in the configuration file. 207W Network Camera is prone to a information disclosure vulnerability

Trust: 1.98

sources: NVD: CVE-2007-4928 // JVNDB: JVNDB-2007-002641 // BID: 85369 // VULHUB: VHN-28290

AFFECTED PRODUCTS

vendor:axismodel:207w network camerascope: - version: -

Trust: 1.4

vendor:axismodel:207w network camerascope:eqversion:*

Trust: 1.0

vendor:axismodel:communications 207w network camerascope:eqversion:0

Trust: 0.3

sources: BID: 85369 // JVNDB: JVNDB-2007-002641 // CNNVD: CNNVD-200709-253 // NVD: CVE-2007-4928

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2007-4928
value: MEDIUM

Trust: 1.0

NVD: CVE-2007-4928
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-200709-253
value: MEDIUM

Trust: 0.6

VULHUB: VHN-28290
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2007-4928
severity: MEDIUM
baseScore: 4.9
vectorString: AV:L/AC:L/AU:N/C:C/I:N/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-28290
severity: MEDIUM
baseScore: 4.9
vectorString: AV:L/AC:L/AU:N/C:C/I:N/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-28290 // JVNDB: JVNDB-2007-002641 // CNNVD: CNNVD-200709-253 // NVD: CVE-2007-4928

PROBLEMTYPE DATA

problemtype:CWE-310

Trust: 1.9

sources: VULHUB: VHN-28290 // JVNDB: JVNDB-2007-002641 // NVD: CVE-2007-4928

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-200709-253

TYPE

encryption problem

Trust: 0.6

sources: CNNVD: CNNVD-200709-253

CONFIGURATIONS

sources: JVNDB: JVNDB-2007-002641

PATCH

title:Top Pageurl:http://www.axis.com/techsup/software/acc/index.htm

Trust: 0.8

sources: JVNDB: JVNDB-2007-002641

EXTERNAL IDS

db:NVDid:CVE-2007-4928

Trust: 2.8

db:SREASONid:3145

Trust: 2.0

db:JVNDBid:JVNDB-2007-002641

Trust: 0.8

db:BUGTRAQid:20070915 AXIS 207W WIRELESS CAMERA WEB INTERFACE - MULTIPLE VULNERABILITIES

Trust: 0.6

db:CNNVDid:CNNVD-200709-253

Trust: 0.6

db:BIDid:85369

Trust: 0.4

db:VULHUBid:VHN-28290

Trust: 0.1

sources: VULHUB: VHN-28290 // BID: 85369 // JVNDB: JVNDB-2007-002641 // CNNVD: CNNVD-200709-253 // NVD: CVE-2007-4928

REFERENCES

url:http://airscanner.com/security/07080701_axis.htm

Trust: 2.0

url:http://www.informit.com/articles/article.aspx?p=1016102

Trust: 2.0

url:http://securityreason.com/securityalert/3145

Trust: 2.0

url:http://www.securityfocus.com/archive/1/479600/100/0/threaded

Trust: 1.1

url:http://www.securityfocus.com/archive/1/archive/1/479600/100/0/threaded

Trust: 0.9

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2007-4928

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2007-4928

Trust: 0.8

sources: VULHUB: VHN-28290 // BID: 85369 // JVNDB: JVNDB-2007-002641 // CNNVD: CNNVD-200709-253 // NVD: CVE-2007-4928

CREDITS

Unknown

Trust: 0.3

sources: BID: 85369

SOURCES

db:VULHUBid:VHN-28290
db:BIDid:85369
db:JVNDBid:JVNDB-2007-002641
db:CNNVDid:CNNVD-200709-253
db:NVDid:CVE-2007-4928

LAST UPDATE DATE

2025-04-10T20:20:42.430000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-28290date:2018-10-15T00:00:00
db:BIDid:85369date:2007-09-18T00:00:00
db:JVNDBid:JVNDB-2007-002641date:2012-06-26T00:00:00
db:CNNVDid:CNNVD-200709-253date:2007-10-08T00:00:00
db:NVDid:CVE-2007-4928date:2025-04-09T00:30:58.490

SOURCES RELEASE DATE

db:VULHUBid:VHN-28290date:2007-09-18T00:00:00
db:BIDid:85369date:2007-09-18T00:00:00
db:JVNDBid:JVNDB-2007-002641date:2012-06-26T00:00:00
db:CNNVDid:CNNVD-200709-253date:2007-09-18T00:00:00
db:NVDid:CVE-2007-4928date:2007-09-18T18:17:00