PT-2024-39240 · Axis · Axis Os

Published

2024-11-26

·

Updated

2024-11-26

·

CVE-2024-8772

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions: AXIS OS versions prior to the patched version
Description: The VAPIX API managedoverlayimages.cgi is vulnerable to a race condition attack, allowing an attacker to block access to the overlay configuration page in the web interface of the Axis device. This flaw can only be exploited after authenticating with an operator- or administrator-privileged service account.
Recommendations: For AXIS OS versions prior to the patched version, update to the patched version as released by Axis to resolve the issue. As a temporary workaround, consider restricting access to the managedoverlayimages.cgi API endpoint until a patch is available.

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-8772

Affected Products

Axis Os