Find a vulnerability
Search criteria
13 vulnerabilities by Axis
CERTFR-2026-AVI-1042
Vulnerability from certfr_avis - Published: 2026-08-19 - Updated: 2026-08-19
De multiples vulnérabilités ont été découvertes dans les produits Axis. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.
Solutions
Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).
| Vendor | Product | Description | ||
|---|---|---|---|---|
| Axis | Active Track | Active Track versions antérieures à 12.11.44 | ||
| Axis | Axis OS | AXIS OS LTS 2024 versions antérieures à 11.11.207 | ||
| Axis | Axis File Player | Axis File Player versions antérieures à 3.1.9.0 | ||
| Axis | Signed-Video-Framework | Signed-Video-Framework versions antérieures à 2.3.5 | ||
| Axis | Signed media verifier | Signed media verifier versions antérieures à 1.0.2 |
| Title | Publication Time | Tags | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
{
"$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
"affected_systems": [
{
"description": "Active Track versions ant\u00e9rieures \u00e0 12.11.44",
"product": {
"name": "Active Track",
"vendor": {
"name": "Axis",
"scada": false
}
}
},
{
"description": "AXIS OS LTS 2024 versions ant\u00e9rieures \u00e0 11.11.207",
"product": {
"name": "Axis OS",
"vendor": {
"name": "Axis",
"scada": false
}
}
},
{
"description": "Axis File Player versions ant\u00e9rieures \u00e0 3.1.9.0",
"product": {
"name": "Axis File Player",
"vendor": {
"name": "Axis",
"scada": false
}
}
},
{
"description": "Signed-Video-Framework versions ant\u00e9rieures \u00e0 2.3.5",
"product": {
"name": "Signed-Video-Framework",
"vendor": {
"name": "Axis",
"scada": false
}
}
},
{
"description": "Signed media verifier versions ant\u00e9rieures \u00e0 1.0.2",
"product": {
"name": "Signed media verifier",
"vendor": {
"name": "Axis",
"scada": false
}
}
}
],
"affected_systems_content": "",
"content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
"cves": [
{
"name": "CVE-2026-6505",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-6505"
},
{
"name": "CVE-2026-6181",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-6181"
},
{
"name": "CVE-2026-5303",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-5303"
},
{
"name": "CVE-2026-8158",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-8158"
},
{
"name": "CVE-2026-4757",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-4757"
},
{
"name": "CVE-2026-5304",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-5304"
}
],
"initial_release_date": "2026-08-19T00:00:00",
"last_revision_date": "2026-08-19T00:00:00",
"links": [],
"reference": "CERTFR-2026-AVI-1042",
"revisions": [
{
"description": "Version initiale",
"revision_date": "2026-08-19T00:00:00.000000"
}
],
"risks": [
{
"description": "D\u00e9ni de service \u00e0 distance"
},
{
"description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
},
{
"description": "Non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur"
},
{
"description": "Contournement de la politique de s\u00e9curit\u00e9"
},
{
"description": "\u00c9l\u00e9vation de privil\u00e8ges"
}
],
"summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits Axis. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire \u00e0 distance, une \u00e9l\u00e9vation de privil\u00e8ges et un d\u00e9ni de service \u00e0 distance.",
"title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits Axis",
"vendor_advisories": [
{
"published_at": "2026-08-18",
"title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2026-5304pdf-en-US-543644",
"url": "https://www.axis.com/dam/public/21/37/f2/cve-2026-5304pdf-en-US-543644.pdf"
},
{
"published_at": "2026-08-18",
"title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2026-8158pdf-en-US-543645",
"url": "https://www.axis.com/dam/public/6c/f3/ac/cve-2026-8158pdf-en-US-543645.pdf"
},
{
"published_at": "2026-08-18",
"title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2026-4757pdf-en-US-543642",
"url": "https://www.axis.com/dam/public/41/7d/0f/cve-2026-4757pdf-en-US-543642.pdf"
},
{
"published_at": "2026-08-18",
"title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2026-5303pdf-en-US-543643",
"url": "https://www.axis.com/dam/public/d5/e8/6e/cve-2026-5303pdf-en-US-543643.pdf"
},
{
"published_at": "2026-08-18",
"title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2026-6181pdf-en-US-543646",
"url": "https://www.axis.com/dam/public/9d/8a/ea/cve-2026-6181pdf-en-US-543646.pdf"
},
{
"published_at": "2026-08-18",
"title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2026-6505pdf-en-US-543641",
"url": "https://www.axis.com/dam/public/fd/16/ab/cve-2026-6505pdf-en-US-543641.pdf"
}
]
}
CERTFR-2026-AVI-0568
Vulnerability from certfr_avis - Published: 2026-05-12 - Updated: 2026-05-12
De multiples vulnérabilités ont été découvertes dans les produits Axis. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance et une élévation de privilèges.
Solutions
Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).
| Title | Publication Time | Tags | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||
{
"$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
"affected_systems": [
{
"description": "Axis OS versions 12.9.x ant\u00e9rieures \u00e0 12.9.33 pour Active Track",
"product": {
"name": "Axis OS",
"vendor": {
"name": "Axis",
"scada": false
}
}
},
{
"description": "Axis OS versions 12.10.x ant\u00e9rieures \u00e0 12.10.37 pour Active Track",
"product": {
"name": "Axis OS",
"vendor": {
"name": "Axis",
"scada": false
}
}
}
],
"affected_systems_content": "",
"content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
"cves": [
{
"name": "CVE-2026-1185",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-1185"
},
{
"name": "CVE-2026-0802",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-0802"
},
{
"name": "CVE-2026-0541",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-0541"
},
{
"name": "CVE-2026-0804",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-0804"
}
],
"initial_release_date": "2026-05-12T00:00:00",
"last_revision_date": "2026-05-12T00:00:00",
"links": [],
"reference": "CERTFR-2026-AVI-0568",
"revisions": [
{
"description": "Version initiale",
"revision_date": "2026-05-12T00:00:00.000000"
}
],
"risks": [
{
"description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
},
{
"description": "\u00c9l\u00e9vation de privil\u00e8ges"
}
],
"summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits Axis. Elles permettent \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire \u00e0 distance et une \u00e9l\u00e9vation de privil\u00e8ges.",
"title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits Axis",
"vendor_advisories": [
{
"published_at": "2026-05-12",
"title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2026-1185pdf-en-US-530733",
"url": "https://www.axis.com/dam/public/69/df/8d/cve-2026-1185pdf-en-US-530733.pdf"
},
{
"published_at": "2026-05-12",
"title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2026-0804pdf-en-US-530732",
"url": "https://www.axis.com/dam/public/51/64/ea/cve-2026-0804pdf-en-US-530732.pdf"
},
{
"published_at": "2026-05-12",
"title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2026-0802pdf-en-US-530731",
"url": "https://www.axis.com/dam/public/67/b8/75/cve-2026-0802pdf-en-US-530731.pdf"
},
{
"published_at": "2026-05-12",
"title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2026-0541pdf-en-US-530730",
"url": "https://www.axis.com/dam/public/fa/50/c7/cve-2026-0541pdf-en-US-530730.pdf"
}
]
}
CERTFR-2026-AVI-0140
Vulnerability from certfr_avis - Published: 2026-02-10 - Updated: 2026-02-10
De multiples vulnérabilités ont été découvertes dans les produits Axis. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et une atteinte à la confidentialité des données.
Solutions
Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).
| Vendor | Product | Description | ||
|---|---|---|---|---|
| Axis | Camera Station Pro | Camera Station Pro versions antérieures à 6.14 | ||
| Axis | Active Track | Active Track versions antérieures à 12.7.36 |
| Title | Publication Time | Tags | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
{
"$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
"affected_systems": [
{
"description": "Camera Station Pro versions ant\u00e9rieures \u00e0 6.14",
"product": {
"name": "Camera Station Pro",
"vendor": {
"name": "Axis",
"scada": false
}
}
},
{
"description": "Active Track versions ant\u00e9rieures \u00e0 12.7.36",
"product": {
"name": "Active Track",
"vendor": {
"name": "Axis",
"scada": false
}
}
}
],
"affected_systems_content": "",
"content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
"cves": [
{
"name": "CVE-2025-13064",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-13064"
},
{
"name": "CVE-2025-11547",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-11547"
},
{
"name": "CVE-2025-12757",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-12757"
},
{
"name": "CVE-2025-12063",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-12063"
},
{
"name": "CVE-2025-11142",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-11142"
}
],
"initial_release_date": "2026-02-10T00:00:00",
"last_revision_date": "2026-02-10T00:00:00",
"links": [],
"reference": "CERTFR-2026-AVI-0140",
"revisions": [
{
"description": "Version initiale",
"revision_date": "2026-02-10T00:00:00.000000"
}
],
"risks": [
{
"description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
},
{
"description": "Contournement de la politique de s\u00e9curit\u00e9"
},
{
"description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
},
{
"description": "\u00c9l\u00e9vation de privil\u00e8ges"
}
],
"summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits Axis. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire \u00e0 distance, une \u00e9l\u00e9vation de privil\u00e8ges et une atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es.",
"title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits Axis",
"vendor_advisories": [
{
"published_at": "2026-02-10",
"title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2025-12063pdf-en-US-519288",
"url": "https://www.axis.com/dam/public/bc/f0/5a/cve-2025-12063pdf-en-US-519288.pdf"
},
{
"published_at": "2026-02-10",
"title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2025-12757pdf-en-US-519289",
"url": "https://www.axis.com/dam/public/de/38/d3/cve-2025-12757pdf-en-US-519289.pdf"
},
{
"published_at": "2026-02-10",
"title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2025-13064pdf-en-US-519290",
"url": "https://www.axis.com/dam/public/a9/9e/94/cve-2025-13064pdf-en-US-519290.pdf"
},
{
"published_at": "2026-02-10",
"title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2025-11142pdf-en-US-519291",
"url": "https://www.axis.com/dam/public/18/0e/90/cve-2025-11142pdf-en-US-519291.pdf"
},
{
"published_at": "2026-02-10",
"title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2025-11547pdf-en-US_253485",
"url": "https://www.axis.com/dam/public/permalink/253485/cve-2025-11547pdf-en-US_253485.pdf"
}
]
}
CERTFR-2026-AVI-0023
Vulnerability from certfr_avis - Published: 2026-01-12 - Updated: 2026-01-12
De multiples vulnérabilités ont été découvertes dans les produits Axis. Elles permettent à un attaquant de provoquer une élévation de privilèges et un déni de service à distance.
Solutions
Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).
| Vendor | Product | Description | ||
|---|---|---|---|---|
| Axis | Axis OS | Axis OS Active Track versions 12.x antérieures à 12.3.4 | ||
| Axis | Axis OS | Axis OS LTS 2022 versions 10.x antérieures à 10.12.270 | ||
| Axis | Axis OS | Axis OS (anciennement LTS) versions 6.x antérieures à 6.50.5.19 | ||
| Axis | Camera Station Pro | Axis Camera Station Pro versions antérieures à 6.8 | ||
| Axis | Axis OS | Axis OS (anciennement LTS) versions 8.x antérieures à 8.40.66 | ||
| Axis | Axis OS | Axis OS LTS 2020 versions 9.x antérieures à 9.80.90 | ||
| Axis | Device Manager | Axis Device Manager versions antérieures à 5.32 | ||
| Axis | Axis OS | Axis OS LTS 2024 versions 11.x antérieures à 11.11.127 |
| Title | Publication Time | Tags | ||||||
|---|---|---|---|---|---|---|---|---|
|
||||||||
{
"$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
"affected_systems": [
{
"description": "Axis OS Active Track versions 12.x ant\u00e9rieures \u00e0 12.3.4",
"product": {
"name": "Axis OS",
"vendor": {
"name": "Axis",
"scada": false
}
}
},
{
"description": "Axis OS LTS 2022 versions 10.x ant\u00e9rieures \u00e0 10.12.270",
"product": {
"name": "Axis OS",
"vendor": {
"name": "Axis",
"scada": false
}
}
},
{
"description": "Axis OS (anciennement LTS) versions 6.x ant\u00e9rieures \u00e0 6.50.5.19",
"product": {
"name": "Axis OS",
"vendor": {
"name": "Axis",
"scada": false
}
}
},
{
"description": "Axis Camera Station Pro versions ant\u00e9rieures \u00e0 6.8",
"product": {
"name": "Camera Station Pro",
"vendor": {
"name": "Axis",
"scada": false
}
}
},
{
"description": "Axis OS (anciennement LTS) versions 8.x ant\u00e9rieures \u00e0 8.40.66",
"product": {
"name": "Axis OS",
"vendor": {
"name": "Axis",
"scada": false
}
}
},
{
"description": "Axis OS LTS 2020 versions 9.x ant\u00e9rieures \u00e0 9.80.90",
"product": {
"name": "Axis OS",
"vendor": {
"name": "Axis",
"scada": false
}
}
},
{
"description": "Axis Device Manager versions ant\u00e9rieures \u00e0 5.32",
"product": {
"name": "Device Manager",
"vendor": {
"name": "Axis",
"scada": false
}
}
},
{
"description": "Axis OS LTS 2024 versions 11.x ant\u00e9rieures \u00e0 11.11.127",
"product": {
"name": "Axis OS",
"vendor": {
"name": "Axis",
"scada": false
}
}
}
],
"affected_systems_content": "",
"content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
"cves": [
{
"name": "CVE-2025-30025",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-30025"
},
{
"name": "CVE-2024-47262",
"url": "https://www.cve.org/CVERecord?id=CVE-2024-47262"
}
],
"initial_release_date": "2026-01-12T00:00:00",
"last_revision_date": "2026-01-12T00:00:00",
"links": [],
"reference": "CERTFR-2026-AVI-0023",
"revisions": [
{
"description": "Version initiale",
"revision_date": "2026-01-12T00:00:00.000000"
}
],
"risks": [
{
"description": "D\u00e9ni de service \u00e0 distance"
},
{
"description": "\u00c9l\u00e9vation de privil\u00e8ges"
}
],
"summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits Axis. Elles permettent \u00e0 un attaquant de provoquer une \u00e9l\u00e9vation de privil\u00e8ges et un d\u00e9ni de service \u00e0 distance.",
"title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits Axis",
"vendor_advisories": [
{
"published_at": "2026-01-12",
"title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2025-30025pdf-en-US-517962",
"url": "https://www.axis.com/dam/public/f2/28/d2/cve-2025-30025pdf-en-US-517962.pdf"
},
{
"published_at": "2026-01-12",
"title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2024-47262pdf-en-US-466884",
"url": "https://www.axis.com/dam/public/a3/18/6e/cve-2024-47262pdf-en-US-466884.pdf"
}
]
}
CERTFR-2025-AVI-0985
Vulnerability from certfr_avis - Published: 2025-11-12 - Updated: 2025-11-12
De multiples vulnérabilités ont été découvertes dans les produits Axis. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.
Solutions
Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).
| Vendor | Product | Description | ||
|---|---|---|---|---|
| Axis | Axis OS | Axis OS (anciennement LTS) versions 6.x antérieures à 6.50.5.22 | ||
| Axis | Optimizer | Axis Optimizer versions antérieures à 5.6.0.0 | ||
| Axis | Axis OS | Axis OS LTS 2024 versions 11.x antérieures à 11.11.178 | ||
| Axis | Axis OS | Axis OS LTS 2022 versions 10.x antérieures à 10.12.306 | ||
| Axis | Axis OS | Axis OS (anciennement LTS) versions 8.x antérieures à 8.40.90 | ||
| Axis | Axis OS | Axis OS LTS 2020 versions 9.x antérieures à 9.80.124 | ||
| Axis | Axis OS | Axis OS Active Track versions 12.x antérieures à 12.7.33 |
{
"$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
"affected_systems": [
{
"description": "Axis OS (anciennement LTS) versions 6.x ant\u00e9rieures \u00e0 6.50.5.22",
"product": {
"name": "Axis OS",
"vendor": {
"name": "Axis",
"scada": false
}
}
},
{
"description": "Axis Optimizer versions ant\u00e9rieures \u00e0 5.6.0.0",
"product": {
"name": "Optimizer",
"vendor": {
"name": "Axis",
"scada": false
}
}
},
{
"description": "Axis OS LTS 2024 versions 11.x ant\u00e9rieures \u00e0 11.11.178",
"product": {
"name": "Axis OS",
"vendor": {
"name": "Axis",
"scada": false
}
}
},
{
"description": "Axis OS LTS 2022 versions 10.x ant\u00e9rieures \u00e0 10.12.306",
"product": {
"name": "Axis OS",
"vendor": {
"name": "Axis",
"scada": false
}
}
},
{
"description": "Axis OS (anciennement LTS) versions 8.x ant\u00e9rieures \u00e0 8.40.90",
"product": {
"name": "Axis OS",
"vendor": {
"name": "Axis",
"scada": false
}
}
},
{
"description": "Axis OS LTS 2020 versions 9.x ant\u00e9rieures \u00e0 9.80.124",
"product": {
"name": "Axis OS",
"vendor": {
"name": "Axis",
"scada": false
}
}
},
{
"description": "Axis OS Active Track versions 12.x ant\u00e9rieures \u00e0 12.7.33",
"product": {
"name": "Axis OS",
"vendor": {
"name": "Axis",
"scada": false
}
}
}
],
"affected_systems_content": "",
"content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
"cves": [
{
"name": "CVE-2025-5718",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-5718"
},
{
"name": "CVE-2025-8108",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-8108"
},
{
"name": "CVE-2025-8998",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-8998"
},
{
"name": "CVE-2025-6571",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-6571"
},
{
"name": "CVE-2025-4645",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-4645"
},
{
"name": "CVE-2025-9524",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-9524"
},
{
"name": "CVE-2025-5454",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-5454"
},
{
"name": "CVE-2025-9055",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-9055"
},
{
"name": "CVE-2025-5452",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-5452"
},
{
"name": "CVE-2025-10714",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-10714"
},
{
"name": "CVE-2025-6298",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-6298"
},
{
"name": "CVE-2025-6779",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-6779"
}
],
"initial_release_date": "2025-11-12T00:00:00",
"last_revision_date": "2025-11-12T00:00:00",
"links": [],
"reference": "CERTFR-2025-AVI-0985",
"revisions": [
{
"description": "Version initiale",
"revision_date": "2025-11-12T00:00:00.000000"
}
],
"risks": [
{
"description": "D\u00e9ni de service \u00e0 distance"
},
{
"description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
},
{
"description": "Contournement de la politique de s\u00e9curit\u00e9"
},
{
"description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
},
{
"description": "\u00c9l\u00e9vation de privil\u00e8ges"
}
],
"summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits Axis. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire \u00e0 distance, une \u00e9l\u00e9vation de privil\u00e8ges et un d\u00e9ni de service \u00e0 distance.",
"title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits Axis",
"vendor_advisories": [
{
"published_at": "2025-11-11",
"title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2025-10714pdf-en-US-504221",
"url": "https://www.axis.com/dam/public/a2/c7/8c/cve-2025-10714pdf-en-US-504221.pdf"
},
{
"published_at": "2025-11-11",
"title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2025-9524pdf-en-US-504220",
"url": "https://www.axis.com/dam/public/f1/f0/1e/cve-2025-9524pdf-en-US-504220.pdf"
},
{
"published_at": "2025-11-11",
"title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2025-8998pdf-en-US-504374",
"url": "https://www.axis.com/dam/public/f5/62/80/cve-2025-8998pdf-en-US-504374.pdf"
},
{
"published_at": "2025-11-11",
"title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2025-6779pdf-en-US-504217",
"url": "https://www.axis.com/dam/public/92/9a/13/cve-2025-6779pdf-en-US-504217.pdf"
},
{
"published_at": "2025-11-11",
"title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2025-4645pdf-en-US-504211",
"url": "https://www.axis.com/dam/public/69/47/ff/cve-2025-4645pdf-en-US-504211.pdf"
},
{
"published_at": "2025-11-11",
"title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2025-9055pdf-en-US-504219",
"url": "https://www.axis.com/dam/public/23/a3/00/cve-2025-9055pdf-en-US-504219.pdf"
},
{
"published_at": "2025-11-11",
"title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2025-6298pdf-en-US-504215",
"url": "https://www.axis.com/dam/public/ef/91/c3/cve-2025-6298pdf-en-US-504215.pdf"
},
{
"published_at": "2025-11-11",
"title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2025-5718pdf-en-US-504214",
"url": "https://www.axis.com/dam/public/3c/a4/6a/cve-2025-5718pdf-en-US-504214.pdf"
},
{
"published_at": "2025-11-11",
"title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2025-5454pdf-en-US-504213",
"url": "https://www.axis.com/dam/public/48/ab/82/cve-2025-5454pdf-en-US-504213.pdf"
},
{
"published_at": "2025-11-11",
"title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2025-8108pdf-en-US-504218",
"url": "https://www.axis.com/dam/public/38/20/aa/cve-2025-8108pdf-en-US-504218.pdf"
},
{
"published_at": "2025-11-11",
"title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2025-5452pdf-en-US-504212",
"url": "https://www.axis.com/dam/public/39/ba/8b/cve-2025-5452pdf-en-US-504212.pdf"
},
{
"published_at": "2025-11-11",
"title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2025-6571pdf-en-US-504216",
"url": "https://www.axis.com/dam/public/1f/f8/f0/cve-2025-6571pdf-en-US-504216.pdf"
}
]
}
CERTFR-2025-AVI-0951
Vulnerability from certfr_avis - Published: 2025-11-03 - Updated: 2025-11-03
De multiples vulnérabilités ont été découvertes dans Axis OS. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.
Solutions
Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).
| Title | Publication Time | Tags | |||
|---|---|---|---|---|---|
|
|||||
{
"$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
"affected_systems": [
{
"description": "Axis OS versions 12.x ant\u00e9rieures \u00e0 12.7",
"product": {
"name": "Axis OS",
"vendor": {
"name": "Axis",
"scada": false
}
}
}
],
"affected_systems_content": "",
"content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
"cves": [
{
"name": "CVE-2025-8108",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-8108"
},
{
"name": "CVE-2025-8998",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-8998"
},
{
"name": "CVE-2025-9524",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-9524"
},
{
"name": "CVE-2025-9055",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-9055"
},
{
"name": "CVE-2025-11142",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-11142"
}
],
"initial_release_date": "2025-11-03T00:00:00",
"last_revision_date": "2025-11-03T00:00:00",
"links": [],
"reference": "CERTFR-2025-AVI-0951",
"revisions": [
{
"description": "Version initiale",
"revision_date": "2025-11-03T00:00:00.000000"
}
],
"risks": [
{
"description": "Non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur"
}
],
"summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans Axis OS. Elles permettent \u00e0 un attaquant de provoquer un probl\u00e8me de s\u00e9curit\u00e9 non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur.",
"title": "Multiples vuln\u00e9rabilit\u00e9s dans Axis OS",
"vendor_advisories": [
{
"published_at": "2025-11-03",
"title": "Bulletin de s\u00e9curit\u00e9 Axis",
"url": "https://help.axis.com/en-us/axis-os-release-notes#axis-os-12"
}
]
}
CERTFR-2024-AVI-1035
Vulnerability from certfr_avis - Published: 2024-12-03 - Updated: 2024-12-03
De multiples vulnérabilités ont été découvertes dans les produits Axis. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.
Solutions
Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).
| Vendor | Product | Description | ||
|---|---|---|---|---|
| Axis | Axis OS | Axis OS LTS 2020 versions 9.80.x antérieures à 9.80.84 sans les derniers correctifs de sécurité | ||
| Axis | Axis OS | Axis OS Active Track versions 12.1.x antérieures à 12.1.28 sans les derniers correctifs de sécurité | ||
| Axis | P1428-E Network Camera | P1428-E Network Camera avec AXIS OS (anciennement LTS) versions antérieures à 6.50.5.19 sans les derniers correctifs de sécurité | ||
| Axis | Camera Station Pro | Camera Station Pro versions antérieures à 6.4 | ||
| Axis | Q6128-E PTZ Network Camera | Q6128-E PTZ Network Camera avec AXIS OS (anciennement LTS) versions antérieures à 6.50.5.19 sans les derniers correctifs de sécurité | ||
| Axis | Axis OS | Axis OS LTS 2022 versions 10.12.x antérieures à 10.12.259 sans les derniers correctifs de sécurité | ||
| Axis | Camera Station | AXIS Camera Station versions antérieures à 5.57.33556 | ||
| Axis | Axis OS | Axis OS LTS 2024 versions 11.11.x antérieures à 11.11.118 sans les derniers correctifs de sécurité |
| Title | Publication Time | Tags | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
{
"$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
"affected_systems": [
{
"description": "Axis OS LTS 2020 versions 9.80.x ant\u00e9rieures \u00e0 9.80.84 sans les derniers correctifs de s\u00e9curit\u00e9",
"product": {
"name": "Axis OS",
"vendor": {
"name": "Axis",
"scada": false
}
}
},
{
"description": "Axis OS Active Track versions 12.1.x ant\u00e9rieures \u00e0 12.1.28 sans les derniers correctifs de s\u00e9curit\u00e9",
"product": {
"name": "Axis OS",
"vendor": {
"name": "Axis",
"scada": false
}
}
},
{
"description": "P1428-E Network Camera avec AXIS OS (anciennement LTS) versions ant\u00e9rieures \u00e0 6.50.5.19 sans les derniers correctifs de s\u00e9curit\u00e9",
"product": {
"name": "P1428-E Network Camera",
"vendor": {
"name": "Axis",
"scada": false
}
}
},
{
"description": "Camera Station Pro versions ant\u00e9rieures \u00e0 6.4",
"product": {
"name": "Camera Station Pro",
"vendor": {
"name": "Axis",
"scada": false
}
}
},
{
"description": "Q6128-E PTZ Network Camera avec AXIS OS (anciennement LTS) versions ant\u00e9rieures \u00e0 6.50.5.19 sans les derniers correctifs de s\u00e9curit\u00e9",
"product": {
"name": "Q6128-E PTZ Network Camera",
"vendor": {
"name": "Axis",
"scada": false
}
}
},
{
"description": "Axis OS LTS 2022 versions 10.12.x ant\u00e9rieures \u00e0 10.12.259 sans les derniers correctifs de s\u00e9curit\u00e9",
"product": {
"name": "Axis OS",
"vendor": {
"name": "Axis",
"scada": false
}
}
},
{
"description": "AXIS Camera Station versions ant\u00e9rieures \u00e0 5.57.33556",
"product": {
"name": "Camera Station",
"vendor": {
"name": "Axis",
"scada": false
}
}
},
{
"description": "Axis OS LTS 2024 versions 11.11.x ant\u00e9rieures \u00e0 11.11.118 sans les derniers correctifs de s\u00e9curit\u00e9",
"product": {
"name": "Axis OS",
"vendor": {
"name": "Axis",
"scada": false
}
}
}
],
"affected_systems_content": "",
"content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
"cves": [
{
"name": "CVE-2024-8772",
"url": "https://www.cve.org/CVERecord?id=CVE-2024-8772"
},
{
"name": "CVE-2024-6749",
"url": "https://www.cve.org/CVERecord?id=CVE-2024-6749"
},
{
"name": "CVE-2024-6476",
"url": "https://www.cve.org/CVERecord?id=CVE-2024-6476"
},
{
"name": "CVE-2024-6831",
"url": "https://www.cve.org/CVERecord?id=CVE-2024-6831"
},
{
"name": "CVE-2024-8160",
"url": "https://www.cve.org/CVERecord?id=CVE-2024-8160"
},
{
"name": "CVE-2024-47257",
"url": "https://www.cve.org/CVERecord?id=CVE-2024-47257"
}
],
"initial_release_date": "2024-12-03T00:00:00",
"last_revision_date": "2024-12-03T00:00:00",
"links": [],
"reference": "CERTFR-2024-AVI-1035",
"revisions": [
{
"description": "Version initiale",
"revision_date": "2024-12-03T00:00:00.000000"
}
],
"risks": [
{
"description": "D\u00e9ni de service \u00e0 distance"
},
{
"description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
},
{
"description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
},
{
"description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
},
{
"description": "\u00c9l\u00e9vation de privil\u00e8ges"
}
],
"summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits Axis. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire \u00e0 distance, une \u00e9l\u00e9vation de privil\u00e8ges et un d\u00e9ni de service \u00e0 distance.",
"title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits Axis",
"vendor_advisories": [
{
"published_at": "2024-11-26",
"title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2024-47257pdf-en-US-458044",
"url": "https://www.axis.com/dam/public/b7/76/b2/cve-2024-47257pdf-en-US-458044.pdf"
},
{
"published_at": "2024-11-26",
"title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2024-6476pdf-en-US-455104",
"url": "https://www.axis.com/dam/public/e5/24/82/cve-2024-6476pdf-en-US-455104.pdf"
},
{
"published_at": "2024-11-26",
"title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2024-6831-en-US-455107",
"url": "https://www.axis.com/dam/public/a2/9a/41/cve-2024-6831-en-US-455107.pdf"
},
{
"published_at": "2024-11-26",
"title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2024-6749-en-US-455106",
"url": "https://www.axis.com/dam/public/e6/e8/1e/cve-2024-6749-en-US-455106.pdf"
},
{
"published_at": "2024-11-26",
"title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2024-8160pdf-en-US_InternalID-231071",
"url": "https://www.axis.com/dam/public/permalink/231071/cve-2024-8160pdf-en-US_InternalID-231071.pdf"
},
{
"published_at": "2024-11-26",
"title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2024-8772pdf-en-US_InternalID-231072",
"url": "https://www.axis.com/dam/public/permalink/231072/cve-2024-8772pdf-en-US_InternalID-231072.pdf"
}
]
}
CVE-2024-7784 (GCVE-0-2024-7784)
Vulnerability from cvelistv5 – Published: 2024-09-10 05:14 – Updated: 2025-03-28 07:23- CWE-121 - Stack-based Buffer Overflow
| Vendor | Product | Version | |
|---|---|---|---|
| Axis Communications AB | AXIS OS |
Affected:
10.9.0 , < 10.12.246
(semver)
Affected: 11.0.0 , < 11.11.80 (semver) Affected: 12.0.0 , < 12.0.40 (semver) |
|
| Axis Communications AB | AXIS OS |
Affected:
11.11.0 , < 11.11.80
(semver)
Affected: 12.0.0 , < 12.0.47 (semver) |
|
| Axis Communications AB | AXIS OS |
Affected:
10.10.0 , < 10.12.247
(semver)
Affected: 11.0.0 , < 11.11.85 (semver) Affected: 12.0.0 , < 12.0.47 (semver) |
|
| Axis Communications AB | AXIS OS |
Affected:
11.8.0 , < 11.11.85
(semver)
Affected: 12.0.0 , < 12.0.47 (semver) |
|
| axis | axis_os |
Affected:
10.9 , < 11.11
(custom)
Affected: 10.10 , < 11.11 (custom) Affected: 11.8 , < 11.11 (custom) cpe:2.3:o:axis:axis_os:*:*:*:*:*:*:*:* |
|
| axis | axis_os |
Affected:
11.11
cpe:2.3:o:axis:axis_os:11.11:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"affected": [
{
"cpes": [
"cpe:2.3:o:axis:axis_os:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "axis_os",
"vendor": "axis",
"versions": [
{
"lessThan": "11.11",
"status": "affected",
"version": "10.9",
"versionType": "custom"
},
{
"lessThan": "11.11",
"status": "affected",
"version": "10.10",
"versionType": "custom"
},
{
"lessThan": "11.11",
"status": "affected",
"version": "11.8",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:o:axis:axis_os:11.11:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "axis_os",
"vendor": "axis",
"versions": [
{
"status": "affected",
"version": "11.11"
}
]
}
],
"metrics": [
{
"other": {
"content": {
"id": "CVE-2024-7784",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-09-10T18:09:41.112495Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-09-10T18:28:46.063Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"platforms": [
"ARTPEC 8"
],
"product": "AXIS OS",
"vendor": "Axis Communications AB",
"versions": [
{
"lessThan": "10.12.246",
"status": "affected",
"version": "10.9.0",
"versionType": "semver"
},
{
"lessThan": "11.11.80",
"status": "affected",
"version": "11.0.0",
"versionType": "semver"
},
{
"lessThan": "12.0.40",
"status": "affected",
"version": "12.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"platforms": [
"i.MX8 QP"
],
"product": "AXIS OS",
"vendor": "Axis Communications AB",
"versions": [
{
"lessThan": "11.11.80",
"status": "affected",
"version": "11.11.0",
"versionType": "semver"
},
{
"lessThan": "12.0.47",
"status": "affected",
"version": "12.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"platforms": [
"i.MX6 SX",
"i.MX6 ULL"
],
"product": "AXIS OS",
"vendor": "Axis Communications AB",
"versions": [
{
"lessThan": "10.12.247",
"status": "affected",
"version": "10.10.0",
"versionType": "semver"
},
{
"lessThan": "11.11.85",
"status": "affected",
"version": "11.0.0",
"versionType": "semver"
},
{
"lessThan": "12.0.47",
"status": "affected",
"version": "12.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"platforms": [
"i.MX8M Mini",
"i.MX8M Nano UL"
],
"product": "AXIS OS",
"vendor": "Axis Communications AB",
"versions": [
{
"lessThan": "11.11.85",
"status": "affected",
"version": "11.8.0",
"versionType": "semver"
},
{
"lessThan": "12.0.47",
"status": "affected",
"version": "12.0.0",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "During internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device tampering (commonly known as Secure Boot) in AXIS OS making it vulnerable to a sophisticated attack to bypass this protection. To Axis\u0027 knowledge, there are no known exploits of the vulnerability at this time. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution."
}
],
"value": "During internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device tampering (commonly known as Secure Boot) in AXIS OS making it vulnerable to a sophisticated attack to bypass this protection. To Axis\u0027 knowledge, there are no known exploits of the vulnerability at this time. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "PHYSICAL",
"availabilityImpact": "NONE",
"baseScore": 6.1,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-121",
"description": "CWE-121: Stack-based Buffer Overflow",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2025-03-28T07:23:28.450Z",
"orgId": "f2daf9a0-02c2-4b83-a01d-63b3b304b807",
"shortName": "Axis"
},
"references": [
{
"url": "https://www.axis.com/dam/public/ba/5f/4e/cve-2024-7784-en-US-448998.pdf"
}
],
"source": {
"discovery": "UNKNOWN"
},
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "f2daf9a0-02c2-4b83-a01d-63b3b304b807",
"assignerShortName": "Axis",
"cveId": "CVE-2024-7784",
"datePublished": "2024-09-10T05:14:33.855Z",
"dateReserved": "2024-08-14T07:55:10.630Z",
"dateUpdated": "2025-03-28T07:23:28.450Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2024-6979 (GCVE-0-2024-6979)
Vulnerability from cvelistv5 – Published: 2024-09-10 05:07 – Updated: 2025-03-28 07:24- CWE-863 - Incorrect Authorization
| Vendor | Product | Version | |
|---|---|---|---|
| Axis Communications AB | AXIS OS |
Affected:
11.11.0 , < 11.11.94
(semver)
|
|
| axis | axis_os |
Affected:
11.11
cpe:2.3:o:axis:axis_os:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"affected": [
{
"cpes": [
"cpe:2.3:o:axis:axis_os:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "axis_os",
"vendor": "axis",
"versions": [
{
"status": "affected",
"version": "11.11"
}
]
}
],
"metrics": [
{
"other": {
"content": {
"id": "CVE-2024-6979",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-09-10T18:16:30.463718Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-09-10T18:26:23.250Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "AXIS OS",
"vendor": "Axis Communications AB",
"versions": [
{
"lessThan": "11.11.94",
"status": "affected",
"version": "11.11.0",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Amin Aliakbari, member of the AXIS OS Bug Bounty Program, has found a broken access control which would lead to less-privileged operator- and/or viewer accounts having more privileges than designed. The risk of exploitation is very low as it requires complex steps to execute, including knowing of account passwords and social engineering attacks in tricking the administrator to perform specific configurations on operator- and/or viewer-privileged accounts. \nAxis has released patched AXIS OS a version for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.\n\n\n\n\u003cbr\u003e"
}
],
"value": "Amin Aliakbari, member of the AXIS OS Bug Bounty Program, has found a broken access control which would lead to less-privileged operator- and/or viewer accounts having more privileges than designed. The risk of exploitation is very low as it requires complex steps to execute, including knowing of account passwords and social engineering attacks in tricking the administrator to perform specific configurations on operator- and/or viewer-privileged accounts. \nAxis has released patched AXIS OS a version for the highlighted flaw. Please refer to the Axis security advisory for more information and solution."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 6.8,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "HIGH",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-863",
"description": "CWE-863: Incorrect Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2025-03-28T07:24:34.043Z",
"orgId": "f2daf9a0-02c2-4b83-a01d-63b3b304b807",
"shortName": "Axis"
},
"references": [
{
"url": "https://www.axis.com/dam/public/c3/44/5b/cve-2024-6979-en-US-448997.pdf"
}
],
"source": {
"discovery": "UNKNOWN"
},
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "f2daf9a0-02c2-4b83-a01d-63b3b304b807",
"assignerShortName": "Axis",
"cveId": "CVE-2024-6979",
"datePublished": "2024-09-10T05:07:42.554Z",
"dateReserved": "2024-07-22T11:34:26.029Z",
"dateUpdated": "2025-03-28T07:24:34.043Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2024-0066 (GCVE-0-2024-0066)
Vulnerability from cvelistv5 – Published: 2024-06-18 06:10 – Updated: 2024-11-08 08:50- CWE-319 - Cleartext Transmission of Sensitive Information
| Vendor | Product | Version | |
|---|---|---|---|
| Axis Communications AB | AXIS OS |
Affected:
AXIS OS 5.51 -11.9
|
|
| axis | axis_os_2020 |
Affected:
0 , < 9.80.69
(custom)
cpe:2.3:o:axis:axis_os_2020:*:*:*:*:lts:*:*:* |
|
| axis | axis_os_2022 |
Affected:
0 , < 10.12.236
(custom)
cpe:2.3:o:axis:axis_os_2022:-:*:*:*:lts:*:*:* |
|
| axis | axis_os |
Affected:
5.51 , ≤ 11.9
(custom)
cpe:2.3:o:axis:axis_os:5.51:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"affected": [
{
"cpes": [
"cpe:2.3:o:axis:axis_os_2020:*:*:*:*:lts:*:*:*"
],
"defaultStatus": "unaffected",
"product": "axis_os_2020",
"vendor": "axis",
"versions": [
{
"lessThan": "9.80.69",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:o:axis:axis_os_2022:-:*:*:*:lts:*:*:*"
],
"defaultStatus": "unaffected",
"product": "axis_os_2022",
"vendor": "axis",
"versions": [
{
"lessThan": "10.12.236",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:o:axis:axis_os:5.51:*:*:*:*:*:*:*"
],
"defaultStatus": "unaffected",
"product": "axis_os",
"vendor": "axis",
"versions": [
{
"lessThanOrEqual": "11.9",
"status": "affected",
"version": "5.51",
"versionType": "custom"
}
]
}
],
"metrics": [
{
"other": {
"content": {
"id": "CVE-2024-0066",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-07-15T19:00:56.546715Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-07-15T20:01:45.648Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
},
{
"providerMetadata": {
"dateUpdated": "2024-08-01T17:41:15.624Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_transferred"
],
"url": "https://www.axis.com/dam/public/03/49/2c/cve-2024-0066-en-US-442553.pdf"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "AXIS OS",
"vendor": "Axis Communications AB",
"versions": [
{
"status": "affected",
"version": "AXIS OS 5.51 -11.9"
}
]
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Johan Fagerstr\u00f6m, member of the AXIS OS Bug Bounty Program, has found that a O3C feature may expose sensitive traffic between the client (Axis device) and (O3C) server. If O3C is not being used this flaw does not apply. \nAxis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution."
}
],
"value": "Johan Fagerstr\u00f6m, member of the AXIS OS Bug Bounty Program, has found that a O3C feature may expose sensitive traffic between the client (Axis device) and (O3C) server. If O3C is not being used this flaw does not apply. \nAxis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-319",
"description": "CWE-319: Cleartext Transmission of Sensitive Information",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-11-08T08:50:35.312Z",
"orgId": "f2daf9a0-02c2-4b83-a01d-63b3b304b807",
"shortName": "Axis"
},
"references": [
{
"url": "https://www.axis.com/dam/public/03/49/2c/cve-2024-0066-en-US-442553.pdf"
}
],
"source": {
"discovery": "UNKNOWN"
},
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "f2daf9a0-02c2-4b83-a01d-63b3b304b807",
"assignerShortName": "Axis",
"cveId": "CVE-2024-0066",
"datePublished": "2024-06-18T06:10:25.800Z",
"dateReserved": "2023-11-22T19:14:29.296Z",
"dateUpdated": "2024-11-08T08:50:35.312Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2023-5553 (GCVE-0-2023-5553)
Vulnerability from cvelistv5 – Published: 2023-11-21 06:59 – Updated: 2025-06-10 14:00- CWE-863 - Incorrect Authorization
| Vendor | Product | Version | |
|---|---|---|---|
| Axis Communications AB | AXIS OS |
Affected:
AXIS OS 10.8 - 11.6
|
|
| axis | axis_os |
Affected:
10.8 , ≤ 11.6
(custom)
cpe:2.3:o:axis:axis_os:*:*:*:*:-:*:*:* |
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-02T07:59:44.904Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_transferred"
],
"url": "https://www.axis.com/dam/public/0a/66/25/cve-2023-5553-en-US-417789.pdf"
}
],
"title": "CVE Program Container"
},
{
"affected": [
{
"cpes": [
"cpe:2.3:o:axis:axis_os:*:*:*:*:-:*:*:*"
],
"defaultStatus": "unknown",
"product": "axis_os",
"vendor": "axis",
"versions": [
{
"lessThanOrEqual": "11.6",
"status": "affected",
"version": "10.8",
"versionType": "custom"
}
]
}
],
"metrics": [
{
"other": {
"content": {
"id": "CVE-2023-5553",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-06-10T14:00:11.680274Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2025-06-10T14:00:37.202Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"platforms": [
"ARTPEC 8"
],
"product": "AXIS OS",
"vendor": "Axis Communications AB",
"versions": [
{
"status": "affected",
"version": "AXIS OS 10.8 - 11.6"
}
]
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "During internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device tampering (commonly known as Secure Boot) in AXIS OS making it vulnerable to a sophisticated attack to bypass this protection. To Axis\u0027 knowledge, there are no known exploits of the vulnerability at this time. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution."
}
],
"value": "During internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device tampering (commonly known as Secure Boot) in AXIS OS making it vulnerable to a sophisticated attack to bypass this protection. To Axis\u0027 knowledge, there are no known exploits of the vulnerability at this time. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "PHYSICAL",
"availabilityImpact": "HIGH",
"baseScore": 7.6,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-863",
"description": "CWE-863: Incorrect Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-11-08T08:25:35.388Z",
"orgId": "f2daf9a0-02c2-4b83-a01d-63b3b304b807",
"shortName": "Axis"
},
"references": [
{
"url": "https://www.axis.com/dam/public/0a/66/25/cve-2023-5553-en-US-417789.pdf"
}
],
"source": {
"discovery": "UNKNOWN"
},
"x_generator": {
"engine": "Vulnogram 0.1.0-dev"
}
}
},
"cveMetadata": {
"assignerOrgId": "f2daf9a0-02c2-4b83-a01d-63b3b304b807",
"assignerShortName": "Axis",
"cveId": "CVE-2023-5553",
"datePublished": "2023-11-21T06:59:42.711Z",
"dateReserved": "2023-10-12T07:06:14.462Z",
"dateUpdated": "2025-06-10T14:00:37.202Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2023-21414 (GCVE-0-2023-21414)
Vulnerability from cvelistv5 – Published: 2023-10-16 06:18 – Updated: 2024-11-08 08:32- CWE-121 - Stack-based Buffer Overflow
| Vendor | Product | Version | |
|---|---|---|---|
| Axis Communications AB | AXIS OS |
Affected:
AXIS OS 10.11 - 11.5
|
|
| Axis Communications AB | AXIS A8207-VE Mk II |
Affected:
AXIS OS 11.5 or earlier
|
|
| Axis Communications AB | AXIS Q3527-LVE |
Affected:
AXIS OS 10.11 - 11.5
|
|
| axis | axis_os |
Affected:
10.11 , ≤ 11.5
(custom)
cpe:2.3:o:axis:axis_os:*:*:*:*:-:*:*:* |
|
| axis | a8207-ve_mk_ii |
Affected:
0 , < 11.5
(custom)
cpe:2.3:o:axis:a8207-ve_mk_ii:*:*:*:*:*:*:*:* |
|
| axis | q3527-lve |
Affected:
10.11 , ≤ 11.5
(custom)
cpe:2.3:o:axis:q3527-lve:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-02T09:36:34.410Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_transferred"
],
"url": "https://www.axis.com/dam/public/45/3c/a1/cve-2023-21414pdf-en-US-412758.pdf"
}
],
"title": "CVE Program Container"
},
{
"affected": [
{
"cpes": [
"cpe:2.3:o:axis:axis_os:*:*:*:*:-:*:*:*"
],
"defaultStatus": "unknown",
"product": "axis_os",
"vendor": "axis",
"versions": [
{
"lessThanOrEqual": "11.5",
"status": "affected",
"version": "10.11",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:o:axis:a8207-ve_mk_ii:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "a8207-ve_mk_ii",
"vendor": "axis",
"versions": [
{
"lessThan": "11.5",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:o:axis:q3527-lve:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "q3527-lve",
"vendor": "axis",
"versions": [
{
"lessThanOrEqual": "11.5",
"status": "affected",
"version": "10.11",
"versionType": "custom"
}
]
}
],
"metrics": [
{
"other": {
"content": {
"id": "CVE-2023-21414",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-09-16T17:32:46.140128Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-09-16T17:42:45.182Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"platforms": [
"ARTPEC 8"
],
"product": "AXIS OS",
"vendor": "Axis Communications AB",
"versions": [
{
"status": "affected",
"version": "AXIS OS 10.11 - 11.5"
}
]
},
{
"defaultStatus": "unaffected",
"product": "AXIS A8207-VE Mk II",
"vendor": "Axis Communications AB",
"versions": [
{
"status": "affected",
"version": "AXIS OS 11.5 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "AXIS Q3527-LVE",
"vendor": "Axis Communications AB",
"versions": [
{
"status": "affected",
"version": "AXIS OS 10.11 - 11.5"
}
]
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "NCC Group has found a flaw during the annual internal penetration test ordered by Axis Communications. The protection for device tampering (commonly known as Secure Boot) contains a flaw which provides an opportunity for a sophisticated attack to bypass this protection. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution."
}
],
"value": "NCC Group has found a flaw during the annual internal penetration test ordered by Axis Communications. The protection for device tampering (commonly known as Secure Boot) contains a flaw which provides an opportunity for a sophisticated attack to bypass this protection. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "PHYSICAL",
"availabilityImpact": "HIGH",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-121",
"description": "CWE-121: Stack-based Buffer Overflow",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-11-08T08:32:47.057Z",
"orgId": "f2daf9a0-02c2-4b83-a01d-63b3b304b807",
"shortName": "Axis"
},
"references": [
{
"url": "https://www.axis.com/dam/public/45/3c/a1/cve-2023-21414pdf-en-US-412758.pdf"
}
],
"source": {
"discovery": "UNKNOWN"
},
"x_generator": {
"engine": "Vulnogram 0.1.0-dev"
}
}
},
"cveMetadata": {
"assignerOrgId": "f2daf9a0-02c2-4b83-a01d-63b3b304b807",
"assignerShortName": "Axis",
"cveId": "CVE-2023-21414",
"datePublished": "2023-10-16T06:18:06.428Z",
"dateReserved": "2022-11-04T18:30:01.767Z",
"dateUpdated": "2024-11-08T08:32:47.057Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2023-21413 (GCVE-0-2023-21413)
Vulnerability from cvelistv5 – Published: 2023-10-16 06:08 – Updated: 2025-06-16 16:51- CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
| Vendor | Product | Version | |
|---|---|---|---|
| Axis Communications AB | AXIS OS |
Affected:
AXIS OS 10.5 – 11.5
|
|
| axis | axis_os |
Affected:
10.5 , ≤ 11.5
(custom)
cpe:2.3:o:axis:axis_os:*:*:*:*:-:*:*:* |
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-02T09:36:34.513Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_transferred"
],
"url": "https://www.axis.com/dam/public/ad/ff/83/cve-2023-21413pdf-en-US-412755.pdf"
}
],
"title": "CVE Program Container"
},
{
"affected": [
{
"cpes": [
"cpe:2.3:o:axis:axis_os:*:*:*:*:-:*:*:*"
],
"defaultStatus": "unknown",
"product": "axis_os",
"vendor": "axis",
"versions": [
{
"lessThanOrEqual": "11.5",
"status": "affected",
"version": "10.5",
"versionType": "custom"
}
]
}
],
"metrics": [
{
"other": {
"content": {
"id": "CVE-2023-21413",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-09-16T17:05:43.917844Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2025-06-16T16:51:55.426Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "AXIS OS",
"vendor": "Axis Communications AB",
"versions": [
{
"status": "affected",
"version": "AXIS OS 10.5 \u2013 11.5"
}
]
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "GoSecure on behalf of Genetec Inc. has found a flaw that allows for a remote code execution during the installation of ACAP applications on the Axis device. The application handling service in AXIS OS was vulnerable to command injection allowing an attacker to run arbitrary code. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.\u003cbr\u003e"
}
],
"value": "GoSecure on behalf of Genetec Inc. has found a flaw that allows for a remote code execution during the installation of ACAP applications on the Axis device. The application handling service in AXIS OS was vulnerable to command injection allowing an attacker to run arbitrary code. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "HIGH",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-78",
"description": "CWE-78: Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-11-08T08:32:01.072Z",
"orgId": "f2daf9a0-02c2-4b83-a01d-63b3b304b807",
"shortName": "Axis"
},
"references": [
{
"url": "https://www.axis.com/dam/public/ad/ff/83/cve-2023-21413pdf-en-US-412755.pdf"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Remote code execution vulnerability during the installation of ACAP applications on the Axis device",
"x_generator": {
"engine": "Vulnogram 0.1.0-dev"
}
}
},
"cveMetadata": {
"assignerOrgId": "f2daf9a0-02c2-4b83-a01d-63b3b304b807",
"assignerShortName": "Axis",
"cveId": "CVE-2023-21413",
"datePublished": "2023-10-16T06:08:33.349Z",
"dateReserved": "2022-11-04T18:30:01.767Z",
"dateUpdated": "2025-06-16T16:51:55.426Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}