ZeroHour

CVE-2024-47259

CVSS 3.1
7.1 high
EPSS
<1%p43
Published
()
Modified
Description

Girishunawane, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API dynamicoverlay.cgi did not have a sufficient input validation allowing for a possible command injection leading to being able to transfer files to the Axis device with the purpose to exhaust system resources. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.

Vendors
axis
Products
axis os, axis os 2024
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H

In the news

No ingested article mentions this CVE yet.