CVE-2024-47261
Last modified
CVE-2024-47261 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. 51l3nc3, a member of the AXIS OS Bug Bounty Program, has found that the VAPIX API uploadoverlayimage.cgi did not have sufficient input validation to allow an attacker to upload files to block access to create image overlays in the web interface of the Axis device.. EPSS estimates a 0.30% chance of exploitation in the next 30 days.
Description
51l3nc3, a member of the AXIS OS Bug Bounty Program, has found that the VAPIX API uploadoverlayimage.cgi did not have sufficient input validation to allow an attacker to upload files to block access to create image overlays in the web interface of the Axis device.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Axis | Axis Os | >= 10.12.0, < 12.3.56 |
| Axis | Axis Os 2022 | < 10.12.276 |
| Axis | Axis Os 2024 | < 11.11.141 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-47261?
How severe is CVE-2024-47261?
How do I fix CVE-2024-47261?
Are you affected by CVE-2024-47261?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
