PT-2024-38017 · Axis Communications · Axis Os

Published

2024-09-09

·

Updated

2024-11-08

·

CVE-2024-6979

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AXIS OS (affected versions not specified)
Description A broken access control issue has been discovered, allowing less-privileged operator- and/or viewer accounts to have more privileges than designed. The risk of exploitation is very low, as it requires complex steps to execute, including knowing account passwords and social engineering attacks to trick the administrator into performing specific configurations on operator- and/or viewer-privileged accounts.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-6979

Affected Products

Axis Os