Vendor CVEs
Axis
All CVEs
122 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-10661 | Cri | 0.74 | 9.8 | 0.87 | Jun 26, 2018 | An issue was discovered in multiple models of Axis IP Cameras. There is a bypass of access control. | ||
| CVE-2018-10662 | Cri | 0.73 | 9.8 | 0.80 | Jun 26, 2018 | An issue was discovered in multiple models of Axis IP Cameras. There is an Exposed Insecure Interface. | ||
| CVE-2018-10660 | Cri | 0.73 | 9.8 | 0.82 | Jun 26, 2018 | An issue was discovered in multiple models of Axis IP Cameras. There is Shell Command Injection. | ||
| CVE-2025-30026 | Cri | 0.64 | 9.8 | 0.01 | Jul 11, 2025 | The AXIS Camera Station Server had a flaw that allowed to bypass authentication that is normally required. | ||
| CVE-2017-20049 | Cri | 0.64 | 9.8 | 0.02 | Jun 15, 2022 | A vulnerability, was found in legacy Axis devices such as P3225 and M3005. This affects an unknown part of the component CGI Script. The manipulation leads to improper privilege management. It is possible to initiate the attack remotely. | ||
| CVE-2015-8257 | Hig | 0.62 | 8.8 | 0.18 | May 2, 2017 | The devtools.sh script in AXIS network cameras allows remote authenticated users to execute arbitrary commands via shell metacharacters in the app parameter to (1) app_license.shtml, (2) app_license_custom.shtml, (3) app_index.shtml, or (4) app_params.shtml. | ||
| CVE-2025-0324 | Cri | 0.61 | 9.4 | 0.00 | Jun 2, 2025 | The VAPIX Device Configuration framework allowed a privilege escalation, enabling a lower-privileged user to gain administrator privileges. | ||
| CVE-2015-8255 | Hig | 0.60 | 8.8 | 0.02 | Apr 10, 2017 | AXIS Communications products allow CSRF, as demonstrated by admin/pwdgrp.cgi, vaconfig.cgi, and admin/local_del.cgi. | ||
| CVE-2025-30023 | Cri | 0.59 | 9.0 | 0.01 | Jul 11, 2025 | The communication protocol used between client and server had a flaw that could lead to an authenticated user performing a remote code execution attack. | ||
| CVE-2023-21413 | Cri | 0.59 | 9.1 | 0.01 | Oct 16, 2023 | GoSecure on behalf of Genetec Inc. has found a flaw that allows for a remote code execution during the installation of ACAP applications on the Axis device. The application handling service in AXIS OS was vulnerable to command injection allowing an attacker to run arbitrary… | ||
| CVE-2025-0358 | Hig | 0.57 | 8.8 | 0.00 | Jun 2, 2025 | During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework that allowed a privilege escalation, enabling a lower-privileged user to gain administrator privileges. | ||
| CVE-2023-21407 | Hig | 0.57 | 8.8 | 0.01 | Aug 3, 2023 | A broken access control was found allowing for privileged escalation of the operator account to gain administrator privileges. | ||
| CVE-2021-31988 | Hig | 0.57 | 8.8 | 0.01 | Oct 5, 2021 | A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to add the Carriage Return and Line Feed (CRLF) control characters and include arbitrary SMTP headers in the generated test email. | ||
| CVE-2025-10714 | Hig | 0.55 | 8.4 | 0.00 | Nov 11, 2025 | AXIS Optimizer was vulnerable to an unquoted search path vulnerability, which could potentially lead to privilege escalation within Microsoft Windows operating system. This vulnerability can only be exploited if the attacker has access to the local Windows machine and sufficient… | ||
| CVE-2025-0359 | Hig | 0.55 | 8.5 | 0.00 | Mar 4, 2025 | During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the ACAP Application framework that allowed applications to access restricted D-Bus methods within the framework. Axis has released patched AXIS OS versions for the… | ||
| CVE-2023-21409 | Hig | 0.55 | 8.4 | 0.01 | Aug 3, 2023 | Due to insufficient file permissions, unprivileged users could gain access to unencrypted administrator credentials allowing the configuration of the application. | ||
| CVE-2023-21408 | Hig | 0.55 | 8.4 | 0.01 | Aug 3, 2023 | Due to insufficient file permissions, unprivileged users could gain access to unencrypted user credentials that are used in the integration interface towards 3rd party systems. | ||
| CVE-2015-8258 | Hig | 0.52 | 7.5 | 0.09 | Apr 10, 2017 | AXIS Communications products with firmware through 5.80.x allow remote attackers to modify arbitrary files as root via vectors involving Open Script Editor, aka a "resource injection vulnerability." | ||
| CVE-2025-11547 | Hig | 0.51 | 7.8 | 0.00 | Feb 10, 2026 | AXIS Camera Station Pro contained a flaw to perform a privilege escalation attack on the server as a non-admin user. | ||
| CVE-2025-30025 | Hig | 0.51 | 7.8 | 0.00 | Jul 11, 2025 | The communication protocol used between the server process and the service control had a flaw that could lead to a local privilege escalation. | ||
| CVE-2025-0360 | Hig | 0.51 | 7.8 | 0.00 | Mar 4, 2025 | During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework that could lead to an incorrect user privilege level in the VAPIX service account D-Bus API. | ||
| CVE-2022-23410 | Hig | 0.51 | 7.8 | 0.00 | Feb 14, 2022 | AXIS IP Utility before 4.18.0 allows for remote code execution and local privilege escalation by the means of DLL hijacking. IPUtility.exe would attempt to load DLLs from its current working directory which could allow for remote code execution if a compromised DLL would be… | ||
| CVE-2024-47257 | Hig | 0.49 | 7.5 | 0.00 | Nov 26, 2024 | Florent Thiéry has found that selected Axis devices were vulnerable to handling certain ethernet frames which could lead to the Axis device becoming unavailable in the network. Axis has released patched AXIS OS versions for the highlighted flaw for products that are still… | ||
| CVE-2023-5553 | Hig | 0.49 | 7.6 | 0.00 | Nov 21, 2023 | During internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device tampering (commonly known as Secure Boot) in AXIS OS making it vulnerable to a sophisticated attack to bypass this protection. To Axis' knowledge, there are no… | ||
| CVE-2021-31987 | Hig | 0.49 | 7.5 | 0.01 | Oct 5, 2021 | A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to bypass blocked network recipients. | ||
| CVE-2018-10664 | Hig | 0.49 | 7.5 | 0.02 | Jun 26, 2018 | An issue was discovered in the httpd process in multiple models of Axis IP Cameras. There is Memory Corruption. | ||
| CVE-2018-10663 | Hig | 0.49 | 7.5 | 0.01 | Jun 26, 2018 | An issue was discovered in multiple models of Axis IP Cameras. There is an Incorrect Size Calculation. | ||
| CVE-2018-10659 | Hig | 0.49 | 7.5 | 0.02 | Jun 26, 2018 | There was a Memory Corruption issue discovered in multiple models of Axis IP Cameras which allows remote attackers to cause a denial of service (crash) by sending a crafted command which will result in a code path that calls the UND undefined ARM instruction. | ||
| CVE-2018-10658 | Hig | 0.49 | 7.5 | 0.02 | Jun 26, 2018 | There was a Memory Corruption issue discovered in multiple models of Axis IP Cameras which causes a denial of service (crash). The crash arises from code inside libdbus-send.so shared object or similar. | ||
| CVE-2018-9158 | Hig | 0.49 | 7.5 | 0.01 | Apr 1, 2018 | An issue was discovered on AXIS M1033-W (IP camera) Firmware version 5.40.5.1 devices. They don't employ a suitable mechanism to prevent a DoS attack, which leads to a response time delay. An attacker can use the hping3 tool to perform an IPv4 flood attack, and the services are… | ||
| CVE-2018-9157 | Hig | 0.49 | 7.5 | 0.03 | Apr 1, 2018 | An issue was discovered on AXIS M1033-W (IP camera) Firmware version 5.40.5.1 devices. The upload web page doesn't verify the file type, and an attacker can upload a webshell by making a fileUpload.shtml request for a custom .shtml file, which is interpreted by the Apache HTTP… | ||
| CVE-2018-9156 | Hig | 0.49 | 7.5 | 0.04 | Apr 1, 2018 | An issue was discovered on AXIS P1354 (IP camera) Firmware version 5.90.1.1 devices. The upload web page doesn't verify the file type, and an attacker can upload a webshell by making a fileUpload.shtml request for a custom .shtml file, which is interpreted by the Apache HTTP… | ||
| CVE-2026-4757 | Hig | 0.47 | 7.2 | 0.00 | Aug 11, 2026 | A VAPIX API parameter had improper input validation which could allow code execution and potentially lead to a privilege escalation. This flaw can only be exploited after authenticating with an administrator-privileged service account. | ||
| CVE-2023-21412 | Hig | 0.47 | 7.2 | 0.01 | Aug 3, 2023 | User provided input is not sanitized on the AXIS License Plate Verifier specific “search.cgi” allowing for SQL injections. | ||
| CVE-2023-21411 | Hig | 0.47 | 7.2 | 0.01 | Aug 3, 2023 | User provided input is not sanitized in the “Settings > Access Control” configuration interface allowing for arbitrary code execution. | ||
| CVE-2023-21410 | Hig | 0.47 | 7.2 | 0.01 | Aug 3, 2023 | User provided input is not sanitized on the AXIS License Plate Verifier specific “api.cgi” allowing for arbitrary code execution. | ||
| CVE-2015-8256 | Med | 0.47 | 6.1 | 0.51 | Apr 17, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in Axis network cameras. | ||
| CVE-2025-11142 | Hig | 0.46 | 7.1 | 0.01 | Feb 10, 2026 | The VAPIX API mediaclip.cgi that did not have a sufficient input validation allowing for a possible remote code execution. This flaw can only be exploited after authenticating with an operator- or administrator- privileged service account. | ||
| CVE-2023-21418 | Hig | 0.46 | 7.1 | 0.01 | Nov 21, 2023 | Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API irissetup.cgi was vulnerable to path traversal attacks that allows for file deletion. This flaw can only be exploited after authenticating with an operator- or administrator-privileged service… | ||
| CVE-2023-21417 | Hig | 0.46 | 7.1 | 0.01 | Nov 21, 2023 | Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API manageoverlayimage.cgi was vulnerable to path traversal attacks that allows for file/folder deletion. This flaw can only be exploited after authenticating with an operator- or administrator-… | ||
| CVE-2023-21416 | Hig | 0.46 | 7.1 | 0.01 | Nov 21, 2023 | Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API dynamicoverlay.cgi was vulnerable to a Denial-of-Service attack allowing for an attacker to block access to the overlay configuration page in the web interface of the Axis device. This flaw can… | ||
| CVE-2023-21414 | Hig | 0.46 | 7.1 | 0.00 | Oct 16, 2023 | NCC Group has found a flaw during the annual internal penetration test ordered by Axis Communications. The protection for device tampering (commonly known as Secure Boot) contains a flaw which provides an opportunity for a sophisticated attack to bypass this protection. Axis has… | ||
| CVE-2023-21406 | Hig | 0.46 | 7.1 | 0.00 | Jul 25, 2023 | Ariel Harush and Roy Hodir from OTORIO have found a flaw in the AXIS A1001 when communicating over OSDP. A heap-based buffer overflow was found in the pacsiod process which is handling the OSDP communication allowing to write outside of the allocated buffer. By appending invalid… | ||
| CVE-2026-0804 | Med | 0.44 | 6.7 | 0.00 | May 12, 2026 | An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to potential privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications,… | ||
| CVE-2026-0541 | Med | 0.44 | 6.7 | 0.00 | May 12, 2026 | ACAP applications can gain elevated privileges due to improper input validation during the installation process, potentially leading to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP… | ||
| CVE-2025-8108 | Med | 0.44 | 6.7 | 0.00 | Nov 11, 2025 | An ACAP configuration file has improper permissions and lacks input validation, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an… | ||
| CVE-2025-6779 | Med | 0.44 | 6.7 | 0.01 | Nov 11, 2025 | An ACAP configuration file has improper permissions, which could allow command injection and potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an… | ||
| CVE-2025-6298 | Med | 0.44 | 6.7 | 0.00 | Nov 11, 2025 | ACAP applications can gain elevated privileges due to improper input validation, potentially leading to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker… | ||
| CVE-2025-5718 | Med | 0.44 | 6.8 | 0.00 | Nov 11, 2025 | The ACAP Application framework could allow privilege escalation through a symlink attack. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a… | ||
| CVE-2025-4645 | Med | 0.44 | 6.7 | 0.00 | Nov 11, 2025 | An ACAP configuration file lacked sufficient input validation, which could allow for arbitrary code execution. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the… |
- risk 0.74cvss 9.8epss 0.87
An issue was discovered in multiple models of Axis IP Cameras. There is a bypass of access control.
- risk 0.73cvss 9.8epss 0.80
An issue was discovered in multiple models of Axis IP Cameras. There is an Exposed Insecure Interface.
- risk 0.73cvss 9.8epss 0.82
An issue was discovered in multiple models of Axis IP Cameras. There is Shell Command Injection.
- risk 0.64cvss 9.8epss 0.01
The AXIS Camera Station Server had a flaw that allowed to bypass authentication that is normally required.
- risk 0.64cvss 9.8epss 0.02
A vulnerability, was found in legacy Axis devices such as P3225 and M3005. This affects an unknown part of the component CGI Script. The manipulation leads to improper privilege management. It is possible to initiate the attack remotely.
- risk 0.62cvss 8.8epss 0.18
The devtools.sh script in AXIS network cameras allows remote authenticated users to execute arbitrary commands via shell metacharacters in the app parameter to (1) app_license.shtml, (2) app_license_custom.shtml, (3) app_index.shtml, or (4) app_params.shtml.
- risk 0.61cvss 9.4epss 0.00
The VAPIX Device Configuration framework allowed a privilege escalation, enabling a lower-privileged user to gain administrator privileges.
- risk 0.60cvss 8.8epss 0.02
AXIS Communications products allow CSRF, as demonstrated by admin/pwdgrp.cgi, vaconfig.cgi, and admin/local_del.cgi.
- risk 0.59cvss 9.0epss 0.01
The communication protocol used between client and server had a flaw that could lead to an authenticated user performing a remote code execution attack.
- risk 0.59cvss 9.1epss 0.01
GoSecure on behalf of Genetec Inc. has found a flaw that allows for a remote code execution during the installation of ACAP applications on the Axis device. The application handling service in AXIS OS was vulnerable to command injection allowing an attacker to run arbitrary…
- risk 0.57cvss 8.8epss 0.00
During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework that allowed a privilege escalation, enabling a lower-privileged user to gain administrator privileges.
- risk 0.57cvss 8.8epss 0.01
A broken access control was found allowing for privileged escalation of the operator account to gain administrator privileges.
- risk 0.57cvss 8.8epss 0.01
A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to add the Carriage Return and Line Feed (CRLF) control characters and include arbitrary SMTP headers in the generated test email.
- risk 0.55cvss 8.4epss 0.00
AXIS Optimizer was vulnerable to an unquoted search path vulnerability, which could potentially lead to privilege escalation within Microsoft Windows operating system. This vulnerability can only be exploited if the attacker has access to the local Windows machine and sufficient…
- risk 0.55cvss 8.5epss 0.00
During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the ACAP Application framework that allowed applications to access restricted D-Bus methods within the framework. Axis has released patched AXIS OS versions for the…
- risk 0.55cvss 8.4epss 0.01
Due to insufficient file permissions, unprivileged users could gain access to unencrypted administrator credentials allowing the configuration of the application.
- risk 0.55cvss 8.4epss 0.01
Due to insufficient file permissions, unprivileged users could gain access to unencrypted user credentials that are used in the integration interface towards 3rd party systems.
- risk 0.52cvss 7.5epss 0.09
AXIS Communications products with firmware through 5.80.x allow remote attackers to modify arbitrary files as root via vectors involving Open Script Editor, aka a "resource injection vulnerability."
- risk 0.51cvss 7.8epss 0.00
AXIS Camera Station Pro contained a flaw to perform a privilege escalation attack on the server as a non-admin user.
- risk 0.51cvss 7.8epss 0.00
The communication protocol used between the server process and the service control had a flaw that could lead to a local privilege escalation.
- risk 0.51cvss 7.8epss 0.00
During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework that could lead to an incorrect user privilege level in the VAPIX service account D-Bus API.
- risk 0.51cvss 7.8epss 0.00
AXIS IP Utility before 4.18.0 allows for remote code execution and local privilege escalation by the means of DLL hijacking. IPUtility.exe would attempt to load DLLs from its current working directory which could allow for remote code execution if a compromised DLL would be…
- risk 0.49cvss 7.5epss 0.00
Florent Thiéry has found that selected Axis devices were vulnerable to handling certain ethernet frames which could lead to the Axis device becoming unavailable in the network. Axis has released patched AXIS OS versions for the highlighted flaw for products that are still…
- risk 0.49cvss 7.6epss 0.00
During internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device tampering (commonly known as Secure Boot) in AXIS OS making it vulnerable to a sophisticated attack to bypass this protection. To Axis' knowledge, there are no…
- risk 0.49cvss 7.5epss 0.01
A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to bypass blocked network recipients.
- risk 0.49cvss 7.5epss 0.02
An issue was discovered in the httpd process in multiple models of Axis IP Cameras. There is Memory Corruption.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in multiple models of Axis IP Cameras. There is an Incorrect Size Calculation.
- risk 0.49cvss 7.5epss 0.02
There was a Memory Corruption issue discovered in multiple models of Axis IP Cameras which allows remote attackers to cause a denial of service (crash) by sending a crafted command which will result in a code path that calls the UND undefined ARM instruction.
- risk 0.49cvss 7.5epss 0.02
There was a Memory Corruption issue discovered in multiple models of Axis IP Cameras which causes a denial of service (crash). The crash arises from code inside libdbus-send.so shared object or similar.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered on AXIS M1033-W (IP camera) Firmware version 5.40.5.1 devices. They don't employ a suitable mechanism to prevent a DoS attack, which leads to a response time delay. An attacker can use the hping3 tool to perform an IPv4 flood attack, and the services are…
- risk 0.49cvss 7.5epss 0.03
An issue was discovered on AXIS M1033-W (IP camera) Firmware version 5.40.5.1 devices. The upload web page doesn't verify the file type, and an attacker can upload a webshell by making a fileUpload.shtml request for a custom .shtml file, which is interpreted by the Apache HTTP…
- risk 0.49cvss 7.5epss 0.04
An issue was discovered on AXIS P1354 (IP camera) Firmware version 5.90.1.1 devices. The upload web page doesn't verify the file type, and an attacker can upload a webshell by making a fileUpload.shtml request for a custom .shtml file, which is interpreted by the Apache HTTP…
- risk 0.47cvss 7.2epss 0.00
A VAPIX API parameter had improper input validation which could allow code execution and potentially lead to a privilege escalation. This flaw can only be exploited after authenticating with an administrator-privileged service account.
- risk 0.47cvss 7.2epss 0.01
User provided input is not sanitized on the AXIS License Plate Verifier specific “search.cgi” allowing for SQL injections.
- risk 0.47cvss 7.2epss 0.01
User provided input is not sanitized in the “Settings > Access Control” configuration interface allowing for arbitrary code execution.
- risk 0.47cvss 7.2epss 0.01
User provided input is not sanitized on the AXIS License Plate Verifier specific “api.cgi” allowing for arbitrary code execution.
- risk 0.47cvss 6.1epss 0.51
Multiple cross-site scripting (XSS) vulnerabilities in Axis network cameras.
- risk 0.46cvss 7.1epss 0.01
The VAPIX API mediaclip.cgi that did not have a sufficient input validation allowing for a possible remote code execution. This flaw can only be exploited after authenticating with an operator- or administrator- privileged service account.
- risk 0.46cvss 7.1epss 0.01
Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API irissetup.cgi was vulnerable to path traversal attacks that allows for file deletion. This flaw can only be exploited after authenticating with an operator- or administrator-privileged service…
- risk 0.46cvss 7.1epss 0.01
Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API manageoverlayimage.cgi was vulnerable to path traversal attacks that allows for file/folder deletion. This flaw can only be exploited after authenticating with an operator- or administrator-…
- risk 0.46cvss 7.1epss 0.01
Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API dynamicoverlay.cgi was vulnerable to a Denial-of-Service attack allowing for an attacker to block access to the overlay configuration page in the web interface of the Axis device. This flaw can…
- risk 0.46cvss 7.1epss 0.00
NCC Group has found a flaw during the annual internal penetration test ordered by Axis Communications. The protection for device tampering (commonly known as Secure Boot) contains a flaw which provides an opportunity for a sophisticated attack to bypass this protection. Axis has…
- risk 0.46cvss 7.1epss 0.00
Ariel Harush and Roy Hodir from OTORIO have found a flaw in the AXIS A1001 when communicating over OSDP. A heap-based buffer overflow was found in the pacsiod process which is handling the OSDP communication allowing to write outside of the allocated buffer. By appending invalid…
- risk 0.44cvss 6.7epss 0.00
An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to potential privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications,…
- risk 0.44cvss 6.7epss 0.00
ACAP applications can gain elevated privileges due to improper input validation during the installation process, potentially leading to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP…
- risk 0.44cvss 6.7epss 0.00
An ACAP configuration file has improper permissions and lacks input validation, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an…
- risk 0.44cvss 6.7epss 0.01
An ACAP configuration file has improper permissions, which could allow command injection and potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an…
- risk 0.44cvss 6.7epss 0.00
ACAP applications can gain elevated privileges due to improper input validation, potentially leading to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker…
- risk 0.44cvss 6.8epss 0.00
The ACAP Application framework could allow privilege escalation through a symlink attack. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a…
- risk 0.44cvss 6.7epss 0.00
An ACAP configuration file lacked sufficient input validation, which could allow for arbitrary code execution. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the…
Page 1 of 3