PT-2024-39240 · Axis · Axis Os
Published
2024-11-26
·
Updated
2024-11-26
·
CVE-2024-8772
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions:
AXIS OS versions prior to the patched version
Description:
The VAPIX API
managedoverlayimages.cgi is vulnerable to a race condition attack, allowing an attacker to block access to the overlay configuration page in the web interface of the Axis device. This flaw can only be exploited after authenticating with an operator- or administrator-privileged service account.Recommendations:
For AXIS OS versions prior to the patched version, update to the patched version as released by Axis to resolve the issue. As a temporary workaround, consider restricting access to the
managedoverlayimages.cgi API endpoint until a patch is available.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Axis Os