PT-2024-37679 · Axis · Axis Os

Published

2024-09-09

·

Updated

2024-11-29

·

CVE-2024-6509

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions AXIS OS (affected versions not specified)
Description The VAPIX API alwaysmulti.cgi is vulnerable to file globbing, which could lead to resource exhaustion of the Axis device. The issue was discovered by Marinus Pfund, a member of the AXIS OS Bug Bounty Program.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Allocation of Resources Without Limits

Improper Neutralization of Wildcards

Weakness Enumeration

Related Identifiers

CVE-2024-6509

Affected Products

Axis Os