CVE-2024-47262
Last modified
CVE-2024-47262 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Dzmitry Lukyanenka, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API param.cgi was vulnerable to a race condition attack allowing for an attacker to block access to the web interface of the Axis device. Other API endpoints or services not making use of param.cgi are not affected. EPSS estimates a 0.33% chance of exploitation in the next 30 days.
Description
Dzmitry Lukyanenka, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API param.cgi was vulnerable to a race condition attack allowing for an attacker to block access to the web interface of the Axis device. Other API endpoints or services not making use of param.cgi are not affected. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-47262?
How severe is CVE-2024-47262?
How do I fix CVE-2024-47262?
Are you affected by CVE-2024-47262?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
