Search

Find a vulnerability

Search criteria

    13 vulnerabilities by axis

    CERTFR-2026-AVI-1042

    Vulnerability from certfr_avis - Published: 2026-08-19 - Updated: 2026-08-19

    De multiples vulnérabilités ont été découvertes dans les produits Axis. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    Axis Active Track Active Track versions antérieures à 12.11.44
    Axis Axis OS AXIS OS LTS 2024 versions antérieures à 11.11.207
    Axis Axis File Player Axis File Player versions antérieures à 3.1.9.0
    Axis Signed-Video-Framework Signed-Video-Framework versions antérieures à 2.3.5
    Axis Signed media verifier Signed media verifier versions antérieures à 1.0.2

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "Active Track versions ant\u00e9rieures \u00e0 12.11.44",
          "product": {
            "name": "Active Track",
            "vendor": {
              "name": "Axis",
              "scada": false
            }
          }
        },
        {
          "description": "AXIS OS LTS 2024 versions ant\u00e9rieures \u00e0 11.11.207",
          "product": {
            "name": "Axis OS",
            "vendor": {
              "name": "Axis",
              "scada": false
            }
          }
        },
        {
          "description": "Axis File Player versions ant\u00e9rieures \u00e0 3.1.9.0",
          "product": {
            "name": "Axis File Player",
            "vendor": {
              "name": "Axis",
              "scada": false
            }
          }
        },
        {
          "description": "Signed-Video-Framework versions ant\u00e9rieures \u00e0 2.3.5",
          "product": {
            "name": "Signed-Video-Framework",
            "vendor": {
              "name": "Axis",
              "scada": false
            }
          }
        },
        {
          "description": "Signed media verifier versions ant\u00e9rieures \u00e0 1.0.2",
          "product": {
            "name": "Signed media verifier",
            "vendor": {
              "name": "Axis",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2026-6505",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6505"
        },
        {
          "name": "CVE-2026-6181",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6181"
        },
        {
          "name": "CVE-2026-5303",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5303"
        },
        {
          "name": "CVE-2026-8158",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-8158"
        },
        {
          "name": "CVE-2026-4757",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-4757"
        },
        {
          "name": "CVE-2026-5304",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5304"
        }
      ],
      "initial_release_date": "2026-08-19T00:00:00",
      "last_revision_date": "2026-08-19T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-1042",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-08-19T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "D\u00e9ni de service \u00e0 distance"
        },
        {
          "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
        },
        {
          "description": "Non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur"
        },
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        },
        {
          "description": "\u00c9l\u00e9vation de privil\u00e8ges"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits Axis. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire \u00e0 distance, une \u00e9l\u00e9vation de privil\u00e8ges et un d\u00e9ni de service \u00e0 distance.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits Axis",
      "vendor_advisories": [
        {
          "published_at": "2026-08-18",
          "title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2026-5304pdf-en-US-543644",
          "url": "https://www.axis.com/dam/public/21/37/f2/cve-2026-5304pdf-en-US-543644.pdf"
        },
        {
          "published_at": "2026-08-18",
          "title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2026-8158pdf-en-US-543645",
          "url": "https://www.axis.com/dam/public/6c/f3/ac/cve-2026-8158pdf-en-US-543645.pdf"
        },
        {
          "published_at": "2026-08-18",
          "title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2026-4757pdf-en-US-543642",
          "url": "https://www.axis.com/dam/public/41/7d/0f/cve-2026-4757pdf-en-US-543642.pdf"
        },
        {
          "published_at": "2026-08-18",
          "title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2026-5303pdf-en-US-543643",
          "url": "https://www.axis.com/dam/public/d5/e8/6e/cve-2026-5303pdf-en-US-543643.pdf"
        },
        {
          "published_at": "2026-08-18",
          "title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2026-6181pdf-en-US-543646",
          "url": "https://www.axis.com/dam/public/9d/8a/ea/cve-2026-6181pdf-en-US-543646.pdf"
        },
        {
          "published_at": "2026-08-18",
          "title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2026-6505pdf-en-US-543641",
          "url": "https://www.axis.com/dam/public/fd/16/ab/cve-2026-6505pdf-en-US-543641.pdf"
        }
      ]
    }

    CERTFR-2026-AVI-0568

    Vulnerability from certfr_avis - Published: 2026-05-12 - Updated: 2026-05-12

    De multiples vulnérabilités ont été découvertes dans les produits Axis. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance et une élévation de privilèges.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    Axis Axis OS Axis OS versions 12.9.x antérieures à 12.9.33 pour Active Track
    Axis Axis OS Axis OS versions 12.10.x antérieures à 12.10.37 pour Active Track
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "Axis OS versions 12.9.x ant\u00e9rieures \u00e0 12.9.33 pour Active Track",
          "product": {
            "name": "Axis OS",
            "vendor": {
              "name": "Axis",
              "scada": false
            }
          }
        },
        {
          "description": "Axis OS versions 12.10.x ant\u00e9rieures \u00e0 12.10.37 pour Active Track",
          "product": {
            "name": "Axis OS",
            "vendor": {
              "name": "Axis",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2026-1185",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-1185"
        },
        {
          "name": "CVE-2026-0802",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0802"
        },
        {
          "name": "CVE-2026-0541",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0541"
        },
        {
          "name": "CVE-2026-0804",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0804"
        }
      ],
      "initial_release_date": "2026-05-12T00:00:00",
      "last_revision_date": "2026-05-12T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-0568",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-05-12T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
        },
        {
          "description": "\u00c9l\u00e9vation de privil\u00e8ges"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits Axis. Elles permettent \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire \u00e0 distance et une \u00e9l\u00e9vation de privil\u00e8ges.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits Axis",
      "vendor_advisories": [
        {
          "published_at": "2026-05-12",
          "title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2026-1185pdf-en-US-530733",
          "url": "https://www.axis.com/dam/public/69/df/8d/cve-2026-1185pdf-en-US-530733.pdf"
        },
        {
          "published_at": "2026-05-12",
          "title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2026-0804pdf-en-US-530732",
          "url": "https://www.axis.com/dam/public/51/64/ea/cve-2026-0804pdf-en-US-530732.pdf"
        },
        {
          "published_at": "2026-05-12",
          "title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2026-0802pdf-en-US-530731",
          "url": "https://www.axis.com/dam/public/67/b8/75/cve-2026-0802pdf-en-US-530731.pdf"
        },
        {
          "published_at": "2026-05-12",
          "title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2026-0541pdf-en-US-530730",
          "url": "https://www.axis.com/dam/public/fa/50/c7/cve-2026-0541pdf-en-US-530730.pdf"
        }
      ]
    }

    CERTFR-2026-AVI-0140

    Vulnerability from certfr_avis - Published: 2026-02-10 - Updated: 2026-02-10

    De multiples vulnérabilités ont été découvertes dans les produits Axis. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et une atteinte à la confidentialité des données.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    Axis Camera Station Pro Camera Station Pro versions antérieures à 6.14
    Axis Active Track Active Track versions antérieures à 12.7.36

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "Camera Station Pro versions ant\u00e9rieures \u00e0 6.14",
          "product": {
            "name": "Camera Station Pro",
            "vendor": {
              "name": "Axis",
              "scada": false
            }
          }
        },
        {
          "description": "Active Track versions ant\u00e9rieures \u00e0 12.7.36",
          "product": {
            "name": "Active Track",
            "vendor": {
              "name": "Axis",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2025-13064",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-13064"
        },
        {
          "name": "CVE-2025-11547",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-11547"
        },
        {
          "name": "CVE-2025-12757",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-12757"
        },
        {
          "name": "CVE-2025-12063",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-12063"
        },
        {
          "name": "CVE-2025-11142",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-11142"
        }
      ],
      "initial_release_date": "2026-02-10T00:00:00",
      "last_revision_date": "2026-02-10T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-0140",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-02-10T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
        },
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        },
        {
          "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
        },
        {
          "description": "\u00c9l\u00e9vation de privil\u00e8ges"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits Axis. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire \u00e0 distance, une \u00e9l\u00e9vation de privil\u00e8ges et une atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits Axis",
      "vendor_advisories": [
        {
          "published_at": "2026-02-10",
          "title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2025-12063pdf-en-US-519288",
          "url": "https://www.axis.com/dam/public/bc/f0/5a/cve-2025-12063pdf-en-US-519288.pdf"
        },
        {
          "published_at": "2026-02-10",
          "title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2025-12757pdf-en-US-519289",
          "url": "https://www.axis.com/dam/public/de/38/d3/cve-2025-12757pdf-en-US-519289.pdf"
        },
        {
          "published_at": "2026-02-10",
          "title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2025-13064pdf-en-US-519290",
          "url": "https://www.axis.com/dam/public/a9/9e/94/cve-2025-13064pdf-en-US-519290.pdf"
        },
        {
          "published_at": "2026-02-10",
          "title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2025-11142pdf-en-US-519291",
          "url": "https://www.axis.com/dam/public/18/0e/90/cve-2025-11142pdf-en-US-519291.pdf"
        },
        {
          "published_at": "2026-02-10",
          "title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2025-11547pdf-en-US_253485",
          "url": "https://www.axis.com/dam/public/permalink/253485/cve-2025-11547pdf-en-US_253485.pdf"
        }
      ]
    }

    CERTFR-2026-AVI-0023

    Vulnerability from certfr_avis - Published: 2026-01-12 - Updated: 2026-01-12

    De multiples vulnérabilités ont été découvertes dans les produits Axis. Elles permettent à un attaquant de provoquer une élévation de privilèges et un déni de service à distance.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    Axis Axis OS Axis OS Active Track versions 12.x antérieures à 12.3.4
    Axis Axis OS Axis OS LTS 2022 versions 10.x antérieures à 10.12.270
    Axis Axis OS Axis OS (anciennement LTS) versions 6.x antérieures à 6.50.5.19
    Axis Camera Station Pro Axis Camera Station Pro versions antérieures à 6.8
    Axis Axis OS Axis OS (anciennement LTS) versions 8.x antérieures à 8.40.66
    Axis Axis OS Axis OS LTS 2020 versions 9.x antérieures à 9.80.90
    Axis Device Manager Axis Device Manager versions antérieures à 5.32
    Axis Axis OS Axis OS LTS 2024 versions 11.x antérieures à 11.11.127
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "Axis OS Active Track versions 12.x ant\u00e9rieures \u00e0 12.3.4",
          "product": {
            "name": "Axis OS",
            "vendor": {
              "name": "Axis",
              "scada": false
            }
          }
        },
        {
          "description": "Axis OS LTS 2022 versions 10.x ant\u00e9rieures \u00e0 10.12.270",
          "product": {
            "name": "Axis OS",
            "vendor": {
              "name": "Axis",
              "scada": false
            }
          }
        },
        {
          "description": "Axis OS (anciennement LTS) versions 6.x ant\u00e9rieures \u00e0 6.50.5.19",
          "product": {
            "name": "Axis OS",
            "vendor": {
              "name": "Axis",
              "scada": false
            }
          }
        },
        {
          "description": "Axis Camera Station Pro versions ant\u00e9rieures \u00e0 6.8",
          "product": {
            "name": "Camera Station Pro",
            "vendor": {
              "name": "Axis",
              "scada": false
            }
          }
        },
        {
          "description": "Axis OS (anciennement LTS) versions 8.x ant\u00e9rieures \u00e0 8.40.66",
          "product": {
            "name": "Axis OS",
            "vendor": {
              "name": "Axis",
              "scada": false
            }
          }
        },
        {
          "description": "Axis OS LTS 2020 versions 9.x ant\u00e9rieures \u00e0 9.80.90",
          "product": {
            "name": "Axis OS",
            "vendor": {
              "name": "Axis",
              "scada": false
            }
          }
        },
        {
          "description": "Axis Device Manager versions ant\u00e9rieures \u00e0 5.32",
          "product": {
            "name": "Device Manager",
            "vendor": {
              "name": "Axis",
              "scada": false
            }
          }
        },
        {
          "description": "Axis OS LTS 2024 versions 11.x ant\u00e9rieures \u00e0 11.11.127",
          "product": {
            "name": "Axis OS",
            "vendor": {
              "name": "Axis",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2025-30025",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-30025"
        },
        {
          "name": "CVE-2024-47262",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-47262"
        }
      ],
      "initial_release_date": "2026-01-12T00:00:00",
      "last_revision_date": "2026-01-12T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-0023",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-01-12T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "D\u00e9ni de service \u00e0 distance"
        },
        {
          "description": "\u00c9l\u00e9vation de privil\u00e8ges"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits Axis. Elles permettent \u00e0 un attaquant de provoquer une \u00e9l\u00e9vation de privil\u00e8ges et un d\u00e9ni de service \u00e0 distance.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits Axis",
      "vendor_advisories": [
        {
          "published_at": "2026-01-12",
          "title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2025-30025pdf-en-US-517962",
          "url": "https://www.axis.com/dam/public/f2/28/d2/cve-2025-30025pdf-en-US-517962.pdf"
        },
        {
          "published_at": "2026-01-12",
          "title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2024-47262pdf-en-US-466884",
          "url": "https://www.axis.com/dam/public/a3/18/6e/cve-2024-47262pdf-en-US-466884.pdf"
        }
      ]
    }

    CERTFR-2025-AVI-0985

    Vulnerability from certfr_avis - Published: 2025-11-12 - Updated: 2025-11-12

    De multiples vulnérabilités ont été découvertes dans les produits Axis. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    Axis Axis OS Axis OS (anciennement LTS) versions 6.x antérieures à 6.50.5.22
    Axis Optimizer Axis Optimizer versions antérieures à 5.6.0.0
    Axis Axis OS Axis OS LTS 2024 versions 11.x antérieures à 11.11.178
    Axis Axis OS Axis OS LTS 2022 versions 10.x antérieures à 10.12.306
    Axis Axis OS Axis OS (anciennement LTS) versions 8.x antérieures à 8.40.90
    Axis Axis OS Axis OS LTS 2020 versions 9.x antérieures à 9.80.124
    Axis Axis OS Axis OS Active Track versions 12.x antérieures à 12.7.33

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "Axis OS (anciennement LTS) versions 6.x ant\u00e9rieures \u00e0 6.50.5.22",
          "product": {
            "name": "Axis OS",
            "vendor": {
              "name": "Axis",
              "scada": false
            }
          }
        },
        {
          "description": "Axis Optimizer versions ant\u00e9rieures \u00e0 5.6.0.0",
          "product": {
            "name": "Optimizer",
            "vendor": {
              "name": "Axis",
              "scada": false
            }
          }
        },
        {
          "description": "Axis OS LTS 2024 versions 11.x ant\u00e9rieures \u00e0 11.11.178",
          "product": {
            "name": "Axis OS",
            "vendor": {
              "name": "Axis",
              "scada": false
            }
          }
        },
        {
          "description": "Axis OS LTS 2022 versions 10.x ant\u00e9rieures \u00e0 10.12.306",
          "product": {
            "name": "Axis OS",
            "vendor": {
              "name": "Axis",
              "scada": false
            }
          }
        },
        {
          "description": "Axis OS (anciennement LTS) versions 8.x ant\u00e9rieures \u00e0 8.40.90",
          "product": {
            "name": "Axis OS",
            "vendor": {
              "name": "Axis",
              "scada": false
            }
          }
        },
        {
          "description": "Axis OS LTS 2020 versions 9.x ant\u00e9rieures \u00e0 9.80.124",
          "product": {
            "name": "Axis OS",
            "vendor": {
              "name": "Axis",
              "scada": false
            }
          }
        },
        {
          "description": "Axis OS Active Track versions 12.x ant\u00e9rieures \u00e0 12.7.33",
          "product": {
            "name": "Axis OS",
            "vendor": {
              "name": "Axis",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2025-5718",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-5718"
        },
        {
          "name": "CVE-2025-8108",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-8108"
        },
        {
          "name": "CVE-2025-8998",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-8998"
        },
        {
          "name": "CVE-2025-6571",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-6571"
        },
        {
          "name": "CVE-2025-4645",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-4645"
        },
        {
          "name": "CVE-2025-9524",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-9524"
        },
        {
          "name": "CVE-2025-5454",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-5454"
        },
        {
          "name": "CVE-2025-9055",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-9055"
        },
        {
          "name": "CVE-2025-5452",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-5452"
        },
        {
          "name": "CVE-2025-10714",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-10714"
        },
        {
          "name": "CVE-2025-6298",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-6298"
        },
        {
          "name": "CVE-2025-6779",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-6779"
        }
      ],
      "initial_release_date": "2025-11-12T00:00:00",
      "last_revision_date": "2025-11-12T00:00:00",
      "links": [],
      "reference": "CERTFR-2025-AVI-0985",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2025-11-12T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "D\u00e9ni de service \u00e0 distance"
        },
        {
          "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
        },
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        },
        {
          "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
        },
        {
          "description": "\u00c9l\u00e9vation de privil\u00e8ges"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits Axis. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire \u00e0 distance, une \u00e9l\u00e9vation de privil\u00e8ges et un d\u00e9ni de service \u00e0 distance.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits Axis",
      "vendor_advisories": [
        {
          "published_at": "2025-11-11",
          "title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2025-10714pdf-en-US-504221",
          "url": "https://www.axis.com/dam/public/a2/c7/8c/cve-2025-10714pdf-en-US-504221.pdf"
        },
        {
          "published_at": "2025-11-11",
          "title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2025-9524pdf-en-US-504220",
          "url": "https://www.axis.com/dam/public/f1/f0/1e/cve-2025-9524pdf-en-US-504220.pdf"
        },
        {
          "published_at": "2025-11-11",
          "title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2025-8998pdf-en-US-504374",
          "url": "https://www.axis.com/dam/public/f5/62/80/cve-2025-8998pdf-en-US-504374.pdf"
        },
        {
          "published_at": "2025-11-11",
          "title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2025-6779pdf-en-US-504217",
          "url": "https://www.axis.com/dam/public/92/9a/13/cve-2025-6779pdf-en-US-504217.pdf"
        },
        {
          "published_at": "2025-11-11",
          "title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2025-4645pdf-en-US-504211",
          "url": "https://www.axis.com/dam/public/69/47/ff/cve-2025-4645pdf-en-US-504211.pdf"
        },
        {
          "published_at": "2025-11-11",
          "title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2025-9055pdf-en-US-504219",
          "url": "https://www.axis.com/dam/public/23/a3/00/cve-2025-9055pdf-en-US-504219.pdf"
        },
        {
          "published_at": "2025-11-11",
          "title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2025-6298pdf-en-US-504215",
          "url": "https://www.axis.com/dam/public/ef/91/c3/cve-2025-6298pdf-en-US-504215.pdf"
        },
        {
          "published_at": "2025-11-11",
          "title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2025-5718pdf-en-US-504214",
          "url": "https://www.axis.com/dam/public/3c/a4/6a/cve-2025-5718pdf-en-US-504214.pdf"
        },
        {
          "published_at": "2025-11-11",
          "title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2025-5454pdf-en-US-504213",
          "url": "https://www.axis.com/dam/public/48/ab/82/cve-2025-5454pdf-en-US-504213.pdf"
        },
        {
          "published_at": "2025-11-11",
          "title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2025-8108pdf-en-US-504218",
          "url": "https://www.axis.com/dam/public/38/20/aa/cve-2025-8108pdf-en-US-504218.pdf"
        },
        {
          "published_at": "2025-11-11",
          "title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2025-5452pdf-en-US-504212",
          "url": "https://www.axis.com/dam/public/39/ba/8b/cve-2025-5452pdf-en-US-504212.pdf"
        },
        {
          "published_at": "2025-11-11",
          "title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2025-6571pdf-en-US-504216",
          "url": "https://www.axis.com/dam/public/1f/f8/f0/cve-2025-6571pdf-en-US-504216.pdf"
        }
      ]
    }

    CERTFR-2025-AVI-0951

    Vulnerability from certfr_avis - Published: 2025-11-03 - Updated: 2025-11-03

    De multiples vulnérabilités ont été découvertes dans Axis OS. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    Axis Axis OS Axis OS versions 12.x antérieures à 12.7
    References
    Bulletin de sécurité Axis 2025-11-03 vendor-advisory

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "Axis OS versions 12.x ant\u00e9rieures \u00e0 12.7",
          "product": {
            "name": "Axis OS",
            "vendor": {
              "name": "Axis",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2025-8108",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-8108"
        },
        {
          "name": "CVE-2025-8998",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-8998"
        },
        {
          "name": "CVE-2025-9524",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-9524"
        },
        {
          "name": "CVE-2025-9055",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-9055"
        },
        {
          "name": "CVE-2025-11142",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-11142"
        }
      ],
      "initial_release_date": "2025-11-03T00:00:00",
      "last_revision_date": "2025-11-03T00:00:00",
      "links": [],
      "reference": "CERTFR-2025-AVI-0951",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2025-11-03T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans Axis OS. Elles permettent \u00e0 un attaquant de provoquer un probl\u00e8me de s\u00e9curit\u00e9 non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans Axis OS",
      "vendor_advisories": [
        {
          "published_at": "2025-11-03",
          "title": "Bulletin de s\u00e9curit\u00e9 Axis",
          "url": "https://help.axis.com/en-us/axis-os-release-notes#axis-os-12"
        }
      ]
    }

    CERTFR-2024-AVI-1035

    Vulnerability from certfr_avis - Published: 2024-12-03 - Updated: 2024-12-03

    De multiples vulnérabilités ont été découvertes dans les produits Axis. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    Axis Axis OS Axis OS LTS 2020 versions 9.80.x antérieures à 9.80.84 sans les derniers correctifs de sécurité
    Axis Axis OS Axis OS Active Track versions 12.1.x antérieures à 12.1.28 sans les derniers correctifs de sécurité
    Axis P1428-E Network Camera P1428-E Network Camera avec AXIS OS (anciennement LTS) versions antérieures à 6.50.5.19 sans les derniers correctifs de sécurité
    Axis Camera Station Pro Camera Station Pro versions antérieures à 6.4
    Axis Q6128-E PTZ Network Camera Q6128-E PTZ Network Camera avec AXIS OS (anciennement LTS) versions antérieures à 6.50.5.19 sans les derniers correctifs de sécurité
    Axis Axis OS Axis OS LTS 2022 versions 10.12.x antérieures à 10.12.259 sans les derniers correctifs de sécurité
    Axis Camera Station AXIS Camera Station versions antérieures à 5.57.33556
    Axis Axis OS Axis OS LTS 2024 versions 11.11.x antérieures à 11.11.118 sans les derniers correctifs de sécurité

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "Axis OS LTS 2020 versions 9.80.x ant\u00e9rieures \u00e0 9.80.84 sans les derniers correctifs de s\u00e9curit\u00e9",
          "product": {
            "name": "Axis OS",
            "vendor": {
              "name": "Axis",
              "scada": false
            }
          }
        },
        {
          "description": "Axis OS Active Track versions 12.1.x ant\u00e9rieures \u00e0 12.1.28 sans les derniers correctifs de s\u00e9curit\u00e9",
          "product": {
            "name": "Axis OS",
            "vendor": {
              "name": "Axis",
              "scada": false
            }
          }
        },
        {
          "description": "P1428-E Network Camera avec AXIS OS (anciennement LTS) versions ant\u00e9rieures \u00e0 6.50.5.19 sans les derniers correctifs de s\u00e9curit\u00e9",
          "product": {
            "name": "P1428-E Network Camera",
            "vendor": {
              "name": "Axis",
              "scada": false
            }
          }
        },
        {
          "description": "Camera Station Pro versions ant\u00e9rieures \u00e0 6.4",
          "product": {
            "name": "Camera Station Pro",
            "vendor": {
              "name": "Axis",
              "scada": false
            }
          }
        },
        {
          "description": "Q6128-E PTZ Network Camera avec AXIS OS (anciennement LTS) versions ant\u00e9rieures \u00e0 6.50.5.19 sans les derniers correctifs de s\u00e9curit\u00e9",
          "product": {
            "name": "Q6128-E PTZ Network Camera",
            "vendor": {
              "name": "Axis",
              "scada": false
            }
          }
        },
        {
          "description": "Axis OS LTS 2022 versions 10.12.x ant\u00e9rieures \u00e0 10.12.259 sans les derniers correctifs de s\u00e9curit\u00e9",
          "product": {
            "name": "Axis OS",
            "vendor": {
              "name": "Axis",
              "scada": false
            }
          }
        },
        {
          "description": "AXIS Camera Station versions ant\u00e9rieures \u00e0 5.57.33556",
          "product": {
            "name": "Camera Station",
            "vendor": {
              "name": "Axis",
              "scada": false
            }
          }
        },
        {
          "description": "Axis OS LTS 2024 versions 11.11.x ant\u00e9rieures \u00e0 11.11.118 sans les derniers correctifs de s\u00e9curit\u00e9",
          "product": {
            "name": "Axis OS",
            "vendor": {
              "name": "Axis",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2024-8772",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-8772"
        },
        {
          "name": "CVE-2024-6749",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-6749"
        },
        {
          "name": "CVE-2024-6476",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-6476"
        },
        {
          "name": "CVE-2024-6831",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-6831"
        },
        {
          "name": "CVE-2024-8160",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-8160"
        },
        {
          "name": "CVE-2024-47257",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-47257"
        }
      ],
      "initial_release_date": "2024-12-03T00:00:00",
      "last_revision_date": "2024-12-03T00:00:00",
      "links": [],
      "reference": "CERTFR-2024-AVI-1035",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2024-12-03T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "D\u00e9ni de service \u00e0 distance"
        },
        {
          "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
        },
        {
          "description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
        },
        {
          "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
        },
        {
          "description": "\u00c9l\u00e9vation de privil\u00e8ges"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits Axis. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire \u00e0 distance, une \u00e9l\u00e9vation de privil\u00e8ges et un d\u00e9ni de service \u00e0 distance.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits Axis",
      "vendor_advisories": [
        {
          "published_at": "2024-11-26",
          "title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2024-47257pdf-en-US-458044",
          "url": "https://www.axis.com/dam/public/b7/76/b2/cve-2024-47257pdf-en-US-458044.pdf"
        },
        {
          "published_at": "2024-11-26",
          "title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2024-6476pdf-en-US-455104",
          "url": "https://www.axis.com/dam/public/e5/24/82/cve-2024-6476pdf-en-US-455104.pdf"
        },
        {
          "published_at": "2024-11-26",
          "title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2024-6831-en-US-455107",
          "url": "https://www.axis.com/dam/public/a2/9a/41/cve-2024-6831-en-US-455107.pdf"
        },
        {
          "published_at": "2024-11-26",
          "title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2024-6749-en-US-455106",
          "url": "https://www.axis.com/dam/public/e6/e8/1e/cve-2024-6749-en-US-455106.pdf"
        },
        {
          "published_at": "2024-11-26",
          "title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2024-8160pdf-en-US_InternalID-231071",
          "url": "https://www.axis.com/dam/public/permalink/231071/cve-2024-8160pdf-en-US_InternalID-231071.pdf"
        },
        {
          "published_at": "2024-11-26",
          "title": "Bulletin de s\u00e9curit\u00e9 Axis cve-2024-8772pdf-en-US_InternalID-231072",
          "url": "https://www.axis.com/dam/public/permalink/231072/cve-2024-8772pdf-en-US_InternalID-231072.pdf"
        }
      ]
    }

    CVE-2024-7784 (GCVE-0-2024-7784)

    Vulnerability from cvelistv5 – Published: 2024-09-10 05:14 – Updated: 2025-03-28 07:23
    VLAI
    Summary
    During internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device tampering (commonly known as Secure Boot) in AXIS OS making it vulnerable to a sophisticated attack to bypass this protection. To Axis' knowledge, there are no known exploits of the vulnerability at this time. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-10 18:09 UTC
    CWE
    • CWE-121 - Stack-based Buffer Overflow
    Impacted products
    Vendor Product Version
    Axis Communications AB AXIS OS Affected: 10.9.0 , < 10.12.246 (semver)
    Affected: 11.0.0 , < 11.11.80 (semver)
    Affected: 12.0.0 , < 12.0.40 (semver)
    Create a notification for this product.
    Axis Communications AB AXIS OS Affected: 11.11.0 , < 11.11.80 (semver)
    Affected: 12.0.0 , < 12.0.47 (semver)
    Create a notification for this product.
    Axis Communications AB AXIS OS Affected: 10.10.0 , < 10.12.247 (semver)
    Affected: 11.0.0 , < 11.11.85 (semver)
    Affected: 12.0.0 , < 12.0.47 (semver)
    Create a notification for this product.
    Axis Communications AB AXIS OS Affected: 11.8.0 , < 11.11.85 (semver)
    Affected: 12.0.0 , < 12.0.47 (semver)
    Create a notification for this product.
    axis axis_os Affected: 10.9 , < 11.11 (custom)
    Affected: 10.10 , < 11.11 (custom)
    Affected: 11.8 , < 11.11 (custom)
        cpe:2.3:o:axis:axis_os:*:*:*:*:*:*:*:*
    Create a notification for this product.
    axis axis_os Affected: 11.11
        cpe:2.3:o:axis:axis_os:11.11:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:axis:axis_os:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "axis_os",
                "vendor": "axis",
                "versions": [
                  {
                    "lessThan": "11.11",
                    "status": "affected",
                    "version": "10.9",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "11.11",
                    "status": "affected",
                    "version": "10.10",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "11.11",
                    "status": "affected",
                    "version": "11.8",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:axis:axis_os:11.11:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "axis_os",
                "vendor": "axis",
                "versions": [
                  {
                    "status": "affected",
                    "version": "11.11"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-7784",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-10T18:09:41.112495Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-10T18:28:46.063Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "ARTPEC 8"
              ],
              "product": "AXIS OS",
              "vendor": "Axis Communications AB",
              "versions": [
                {
                  "lessThan": "10.12.246",
                  "status": "affected",
                  "version": "10.9.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "11.11.80",
                  "status": "affected",
                  "version": "11.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "12.0.40",
                  "status": "affected",
                  "version": "12.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "i.MX8 QP"
              ],
              "product": "AXIS OS",
              "vendor": "Axis Communications AB",
              "versions": [
                {
                  "lessThan": "11.11.80",
                  "status": "affected",
                  "version": "11.11.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "12.0.47",
                  "status": "affected",
                  "version": "12.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "i.MX6 SX",
                "i.MX6 ULL"
              ],
              "product": "AXIS OS",
              "vendor": "Axis Communications AB",
              "versions": [
                {
                  "lessThan": "10.12.247",
                  "status": "affected",
                  "version": "10.10.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "11.11.85",
                  "status": "affected",
                  "version": "11.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "12.0.47",
                  "status": "affected",
                  "version": "12.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "i.MX8M Mini",
                "i.MX8M Nano UL"
              ],
              "product": "AXIS OS",
              "vendor": "Axis Communications AB",
              "versions": [
                {
                  "lessThan": "11.11.85",
                  "status": "affected",
                  "version": "11.8.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "12.0.47",
                  "status": "affected",
                  "version": "12.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "During internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device tampering (commonly known as Secure Boot) in AXIS OS making it vulnerable to a sophisticated attack to bypass this protection. To Axis\u0027 knowledge, there are no known exploits of the vulnerability at this time. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution."
                }
              ],
              "value": "During internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device tampering (commonly known as Secure Boot) in AXIS OS making it vulnerable to a sophisticated attack to bypass this protection. To Axis\u0027 knowledge, there are no known exploits of the vulnerability at this time. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "PHYSICAL",
                "availabilityImpact": "NONE",
                "baseScore": 6.1,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-121",
                  "description": "CWE-121: Stack-based Buffer Overflow",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-03-28T07:23:28.450Z",
            "orgId": "f2daf9a0-02c2-4b83-a01d-63b3b304b807",
            "shortName": "Axis"
          },
          "references": [
            {
              "url": "https://www.axis.com/dam/public/ba/5f/4e/cve-2024-7784-en-US-448998.pdf"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f2daf9a0-02c2-4b83-a01d-63b3b304b807",
        "assignerShortName": "Axis",
        "cveId": "CVE-2024-7784",
        "datePublished": "2024-09-10T05:14:33.855Z",
        "dateReserved": "2024-08-14T07:55:10.630Z",
        "dateUpdated": "2025-03-28T07:23:28.450Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-6979 (GCVE-0-2024-6979)

    Vulnerability from cvelistv5 – Published: 2024-09-10 05:07 – Updated: 2025-03-28 07:24
    VLAI
    Summary
    Amin Aliakbari, member of the AXIS OS Bug Bounty Program, has found a broken access control which would lead to less-privileged operator- and/or viewer accounts having more privileges than designed. The risk of exploitation is very low as it requires complex steps to execute, including knowing of account passwords and social engineering attacks in tricking the administrator to perform specific configurations on operator- and/or viewer-privileged accounts. Axis has released patched AXIS OS a version for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-10 18:16 UTC
    CWE
    • CWE-863 - Incorrect Authorization
    Impacted products
    Vendor Product Version
    Axis Communications AB AXIS OS Affected: 11.11.0 , < 11.11.94 (semver)
    Create a notification for this product.
    axis axis_os Affected: 11.11
        cpe:2.3:o:axis:axis_os:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:axis:axis_os:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "axis_os",
                "vendor": "axis",
                "versions": [
                  {
                    "status": "affected",
                    "version": "11.11"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-6979",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-10T18:16:30.463718Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-10T18:26:23.250Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "AXIS OS",
              "vendor": "Axis Communications AB",
              "versions": [
                {
                  "lessThan": "11.11.94",
                  "status": "affected",
                  "version": "11.11.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Amin Aliakbari, member of the AXIS OS Bug Bounty Program, has found a broken access control which would lead to less-privileged operator- and/or viewer accounts having more privileges than designed. The risk of exploitation is very low as it requires complex steps to execute, including knowing of account passwords and social engineering attacks in tricking the administrator to perform specific configurations on operator- and/or viewer-privileged accounts. \nAxis has released patched AXIS OS a version for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.\n\n\n\n\u003cbr\u003e"
                }
              ],
              "value": "Amin Aliakbari, member of the AXIS OS Bug Bounty Program, has found a broken access control which would lead to less-privileged operator- and/or viewer accounts having more privileges than designed. The risk of exploitation is very low as it requires complex steps to execute, including knowing of account passwords and social engineering attacks in tricking the administrator to perform specific configurations on operator- and/or viewer-privileged accounts. \nAxis has released patched AXIS OS a version for the highlighted flaw. Please refer to the Axis security advisory for more information and solution."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 6.8,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-863",
                  "description": "CWE-863: Incorrect Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-03-28T07:24:34.043Z",
            "orgId": "f2daf9a0-02c2-4b83-a01d-63b3b304b807",
            "shortName": "Axis"
          },
          "references": [
            {
              "url": "https://www.axis.com/dam/public/c3/44/5b/cve-2024-6979-en-US-448997.pdf"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f2daf9a0-02c2-4b83-a01d-63b3b304b807",
        "assignerShortName": "Axis",
        "cveId": "CVE-2024-6979",
        "datePublished": "2024-09-10T05:07:42.554Z",
        "dateReserved": "2024-07-22T11:34:26.029Z",
        "dateUpdated": "2025-03-28T07:24:34.043Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-0066 (GCVE-0-2024-0066)

    Vulnerability from cvelistv5 – Published: 2024-06-18 06:10 – Updated: 2024-11-08 08:50
    VLAI
    Summary
    Johan Fagerström, member of the AXIS OS Bug Bounty Program, has found that a O3C feature may expose sensitive traffic between the client (Axis device) and (O3C) server. If O3C is not being used this flaw does not apply. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-07-15 19:00 UTC
    CWE
    • CWE-319 - Cleartext Transmission of Sensitive Information
    Impacted products
    Vendor Product Version
    Axis Communications AB AXIS OS Affected: AXIS OS 5.51 -11.9
    Create a notification for this product.
    axis axis_os_2020 Affected: 0 , < 9.80.69 (custom)
        cpe:2.3:o:axis:axis_os_2020:*:*:*:*:lts:*:*:*
    Create a notification for this product.
    axis axis_os_2022 Affected: 0 , < 10.12.236 (custom)
        cpe:2.3:o:axis:axis_os_2022:-:*:*:*:lts:*:*:*
    Create a notification for this product.
    axis axis_os Affected: 5.51 , ≤ 11.9 (custom)
        cpe:2.3:o:axis:axis_os:5.51:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:axis:axis_os_2020:*:*:*:*:lts:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "axis_os_2020",
                "vendor": "axis",
                "versions": [
                  {
                    "lessThan": "9.80.69",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:axis:axis_os_2022:-:*:*:*:lts:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "axis_os_2022",
                "vendor": "axis",
                "versions": [
                  {
                    "lessThan": "10.12.236",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:axis:axis_os:5.51:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "axis_os",
                "vendor": "axis",
                "versions": [
                  {
                    "lessThanOrEqual": "11.9",
                    "status": "affected",
                    "version": "5.51",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-0066",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-07-15T19:00:56.546715Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-07-15T20:01:45.648Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T17:41:15.624Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.axis.com/dam/public/03/49/2c/cve-2024-0066-en-US-442553.pdf"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "AXIS OS",
              "vendor": "Axis Communications AB",
              "versions": [
                {
                  "status": "affected",
                  "version": "AXIS OS 5.51 -11.9"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Johan Fagerstr\u00f6m, member of the AXIS OS Bug Bounty Program, has found that a O3C feature may expose sensitive traffic between the client (Axis device) and (O3C) server. If O3C is not being used this flaw does not apply. \nAxis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution."
                }
              ],
              "value": "Johan Fagerstr\u00f6m, member of the AXIS OS Bug Bounty Program, has found that a O3C feature may expose sensitive traffic between the client (Axis device) and (O3C) server. If O3C is not being used this flaw does not apply. \nAxis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-319",
                  "description": "CWE-319: Cleartext Transmission of Sensitive Information",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-11-08T08:50:35.312Z",
            "orgId": "f2daf9a0-02c2-4b83-a01d-63b3b304b807",
            "shortName": "Axis"
          },
          "references": [
            {
              "url": "https://www.axis.com/dam/public/03/49/2c/cve-2024-0066-en-US-442553.pdf"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f2daf9a0-02c2-4b83-a01d-63b3b304b807",
        "assignerShortName": "Axis",
        "cveId": "CVE-2024-0066",
        "datePublished": "2024-06-18T06:10:25.800Z",
        "dateReserved": "2023-11-22T19:14:29.296Z",
        "dateUpdated": "2024-11-08T08:50:35.312Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-5553 (GCVE-0-2023-5553)

    Vulnerability from cvelistv5 – Published: 2023-11-21 06:59 – Updated: 2025-06-10 14:00
    VLAI
    Summary
    During internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device tampering (commonly known as Secure Boot) in AXIS OS making it vulnerable to a sophisticated attack to bypass this protection. To Axis' knowledge, there are no known exploits of the vulnerability at this time. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-06-10 14:00 UTC
    CWE
    • CWE-863 - Incorrect Authorization
    Impacted products
    Vendor Product Version
    Axis Communications AB AXIS OS Affected: AXIS OS 10.8 - 11.6
    Create a notification for this product.
    axis axis_os Affected: 10.8 , ≤ 11.6 (custom)
        cpe:2.3:o:axis:axis_os:*:*:*:*:-:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T07:59:44.904Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.axis.com/dam/public/0a/66/25/cve-2023-5553-en-US-417789.pdf"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:axis:axis_os:*:*:*:*:-:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "axis_os",
                "vendor": "axis",
                "versions": [
                  {
                    "lessThanOrEqual": "11.6",
                    "status": "affected",
                    "version": "10.8",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-5553",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-06-10T14:00:11.680274Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-06-10T14:00:37.202Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "ARTPEC 8"
              ],
              "product": "AXIS OS",
              "vendor": "Axis Communications AB",
              "versions": [
                {
                  "status": "affected",
                  "version": "AXIS OS 10.8 - 11.6"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "During internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device tampering (commonly known as Secure Boot) in AXIS OS making it vulnerable to a sophisticated attack to bypass this protection. To Axis\u0027 knowledge, there are no known exploits of the vulnerability at this time. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution."
                }
              ],
              "value": "During internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device tampering (commonly known as Secure Boot) in AXIS OS making it vulnerable to a sophisticated attack to bypass this protection. To Axis\u0027 knowledge, there are no known exploits of the vulnerability at this time. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "PHYSICAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.6,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-863",
                  "description": "CWE-863: Incorrect Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-11-08T08:25:35.388Z",
            "orgId": "f2daf9a0-02c2-4b83-a01d-63b3b304b807",
            "shortName": "Axis"
          },
          "references": [
            {
              "url": "https://www.axis.com/dam/public/0a/66/25/cve-2023-5553-en-US-417789.pdf"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f2daf9a0-02c2-4b83-a01d-63b3b304b807",
        "assignerShortName": "Axis",
        "cveId": "CVE-2023-5553",
        "datePublished": "2023-11-21T06:59:42.711Z",
        "dateReserved": "2023-10-12T07:06:14.462Z",
        "dateUpdated": "2025-06-10T14:00:37.202Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-21414 (GCVE-0-2023-21414)

    Vulnerability from cvelistv5 – Published: 2023-10-16 06:18 – Updated: 2024-11-08 08:32
    VLAI
    Summary
    NCC Group has found a flaw during the annual internal penetration test ordered by Axis Communications. The protection for device tampering (commonly known as Secure Boot) contains a flaw which provides an opportunity for a sophisticated attack to bypass this protection. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-16 17:32 UTC
    CWE
    • CWE-121 - Stack-based Buffer Overflow
    Impacted products
    Vendor Product Version
    Axis Communications AB AXIS OS Affected: AXIS OS 10.11 - 11.5
    Create a notification for this product.
    Axis Communications AB AXIS A8207-VE Mk II Affected: AXIS OS 11.5 or earlier
    Create a notification for this product.
    Axis Communications AB AXIS Q3527-LVE Affected: AXIS OS 10.11 - 11.5
    Create a notification for this product.
    axis axis_os Affected: 10.11 , ≤ 11.5 (custom)
        cpe:2.3:o:axis:axis_os:*:*:*:*:-:*:*:*
    Create a notification for this product.
    axis a8207-ve_mk_ii Affected: 0 , < 11.5 (custom)
        cpe:2.3:o:axis:a8207-ve_mk_ii:*:*:*:*:*:*:*:*
    Create a notification for this product.
    axis q3527-lve Affected: 10.11 , ≤ 11.5 (custom)
        cpe:2.3:o:axis:q3527-lve:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T09:36:34.410Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.axis.com/dam/public/45/3c/a1/cve-2023-21414pdf-en-US-412758.pdf"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:axis:axis_os:*:*:*:*:-:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "axis_os",
                "vendor": "axis",
                "versions": [
                  {
                    "lessThanOrEqual": "11.5",
                    "status": "affected",
                    "version": "10.11",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:axis:a8207-ve_mk_ii:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "a8207-ve_mk_ii",
                "vendor": "axis",
                "versions": [
                  {
                    "lessThan": "11.5",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:axis:q3527-lve:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "q3527-lve",
                "vendor": "axis",
                "versions": [
                  {
                    "lessThanOrEqual": "11.5",
                    "status": "affected",
                    "version": "10.11",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-21414",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-16T17:32:46.140128Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-16T17:42:45.182Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "ARTPEC 8"
              ],
              "product": "AXIS OS",
              "vendor": "Axis Communications AB",
              "versions": [
                {
                  "status": "affected",
                  "version": "AXIS OS 10.11 - 11.5"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "AXIS A8207-VE Mk II",
              "vendor": "Axis Communications AB",
              "versions": [
                {
                  "status": "affected",
                  "version": "AXIS OS 11.5 or earlier"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "AXIS Q3527-LVE",
              "vendor": "Axis Communications AB",
              "versions": [
                {
                  "status": "affected",
                  "version": "AXIS OS 10.11 - 11.5"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "NCC Group has found a flaw during the annual internal penetration test ordered by Axis Communications. The protection for device tampering (commonly known as Secure Boot) contains a flaw which provides an opportunity for a sophisticated attack to bypass this protection. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution."
                }
              ],
              "value": "NCC Group has found a flaw during the annual internal penetration test ordered by Axis Communications. The protection for device tampering (commonly known as Secure Boot) contains a flaw which provides an opportunity for a sophisticated attack to bypass this protection. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "PHYSICAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-121",
                  "description": "CWE-121: Stack-based Buffer Overflow",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-11-08T08:32:47.057Z",
            "orgId": "f2daf9a0-02c2-4b83-a01d-63b3b304b807",
            "shortName": "Axis"
          },
          "references": [
            {
              "url": "https://www.axis.com/dam/public/45/3c/a1/cve-2023-21414pdf-en-US-412758.pdf"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f2daf9a0-02c2-4b83-a01d-63b3b304b807",
        "assignerShortName": "Axis",
        "cveId": "CVE-2023-21414",
        "datePublished": "2023-10-16T06:18:06.428Z",
        "dateReserved": "2022-11-04T18:30:01.767Z",
        "dateUpdated": "2024-11-08T08:32:47.057Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-21413 (GCVE-0-2023-21413)

    Vulnerability from cvelistv5 – Published: 2023-10-16 06:08 – Updated: 2025-06-16 16:51
    VLAI
    Title
    Remote code execution vulnerability during the installation of ACAP applications on the Axis device
    Summary
    GoSecure on behalf of Genetec Inc. has found a flaw that allows for a remote code execution during the installation of ACAP applications on the Axis device. The application handling service in AXIS OS was vulnerable to command injection allowing an attacker to run arbitrary code. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-16 17:05 UTC
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    Impacted products
    Vendor Product Version
    Axis Communications AB AXIS OS Affected: AXIS OS 10.5 – 11.5
    Create a notification for this product.
    axis axis_os Affected: 10.5 , ≤ 11.5 (custom)
        cpe:2.3:o:axis:axis_os:*:*:*:*:-:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T09:36:34.513Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.axis.com/dam/public/ad/ff/83/cve-2023-21413pdf-en-US-412755.pdf"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:axis:axis_os:*:*:*:*:-:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "axis_os",
                "vendor": "axis",
                "versions": [
                  {
                    "lessThanOrEqual": "11.5",
                    "status": "affected",
                    "version": "10.5",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-21413",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-16T17:05:43.917844Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-06-16T16:51:55.426Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "AXIS OS",
              "vendor": "Axis Communications AB",
              "versions": [
                {
                  "status": "affected",
                  "version": "AXIS OS 10.5 \u2013 11.5"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "GoSecure on behalf of Genetec Inc. has found a flaw that allows for a remote code execution during the installation of ACAP applications on the Axis device. The application handling service in AXIS OS was vulnerable to command injection allowing an attacker to run arbitrary code. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.\u003cbr\u003e"
                }
              ],
              "value": "GoSecure on behalf of Genetec Inc. has found a flaw that allows for a remote code execution during the installation of ACAP applications on the Axis device. The application handling service in AXIS OS was vulnerable to command injection allowing an attacker to run arbitrary code. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.1,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78: Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-11-08T08:32:01.072Z",
            "orgId": "f2daf9a0-02c2-4b83-a01d-63b3b304b807",
            "shortName": "Axis"
          },
          "references": [
            {
              "url": "https://www.axis.com/dam/public/ad/ff/83/cve-2023-21413pdf-en-US-412755.pdf"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Remote code execution vulnerability during the installation of ACAP applications on the Axis device",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f2daf9a0-02c2-4b83-a01d-63b3b304b807",
        "assignerShortName": "Axis",
        "cveId": "CVE-2023-21413",
        "datePublished": "2023-10-16T06:08:33.349Z",
        "dateReserved": "2022-11-04T18:30:01.767Z",
        "dateUpdated": "2025-06-16T16:51:55.426Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }