CameraRisk

CVE-2004-0789

Axis Communications

Published
31 December 2004
Last modified
16 June 2026
CVSS
5.0 v2.0
Severity
medium
EPSS
2.8% (85th pct)
CISA KEV
Not listed
NVD status
Modified
Weaknesses
None assigned

AV:N/AC:L/Au:N/C:N/I:N/A:P

Description

Multiple implementations of the DNS protocol, including (1) Poslib 1.0.2-1 and earlier as used by Posadis, (2) Axis Network products before firmware 3.13, and (3) Men & Mice Suite 2.2x before 2.2.3 and 3.5.x before 3.5.2, allow remote attackers to cause a denial of service (CPU and network bandwidth consumption) by triggering a communications loop via (a) DNS query packets with localhost as a spoofed source address, or (b) a response packet that triggers a response packet.

Exploitation

Not listed in the CISA Known Exploited Vulnerabilities catalogue as of 2026.09.04. That is an absence of confirmed public exploitation, not evidence that exploitation has not occurred. EPSS models a 2.8% probability of exploitation activity in the next 30 days.

Affected products

ProductVendorTypeVersions named
2100 NETWORK CAMERA Axis Communications IP camera 2.0, 2.01, 2.02, 2.03 +13
2110 NETWORK CAMERA Axis Communications IP camera 2.12, 2.30, 2.31, 2.32 +5
2120 NETWORK CAMERA Axis Communications IP camera 2.12, 2.30, 2.31, 2.32 +5
2400 VIDEO SERVER Axis Communications Video management software 1.1, 1.10, 1.11, 1.12 +13
2401 VIDEO SERVER Axis Communications Video management software 1.0_1, 1.15, 2.20, 2.30 +8
2420 NETWORK CAMERA Axis Communications IP camera 2.12, 2.30, 2.31, 2.32 +6
2460 NETWORK DVR Axis Communications Digital video recorder 3.10, 3.11, 3.12, <= 3.00

References

Vendor advisory and patch

CVE-2004-0789 at NVD

Record assembled from NVD, CISA KEV 2026.09.04 and FIRST EPSS 2026-09-04. Affected products are those NVD's CPE configuration names that fall inside this site's scope; a CVE may affect products outside it.