2291
|
- |
|
-
|
-
|
Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX APIs local_list.cgi, create_overlay.cgi and irissetup.cgi was vulnerable for file globbing which could lead to a resou…
|
-
|
CVE-2024-0054
|
2024-11-8 18:15 |
2024-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2292
|
8.8 |
HIGH
Network
|
axis
|
axis_os axis_os_2022 axis_os_2020
|
Vintage,
member of the AXIS OS Bug Bounty Program, has found that the VAPIX API create_overlay.cgi
did not have a sufficient input validation allowing for a possible remote code
execution. This flaw …
|
CWE-94
Code Injection
|
CVE-2023-5800
|
2024-11-8 18:15 |
2024-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2293
|
6.8 |
MEDIUM
Physics
|
axis
|
axis_os_2022 axis_os
|
During internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device tampering (commonly known as Secure Boot) in AXIS OS making it vulnerable to a s…
|
NVD-CWE-noinfo
|
CVE-2023-5553
|
2024-11-8 18:15 |
2023-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2294
|
6.5 |
MEDIUM
Network
|
axis
|
axis_os axis_os_2022
|
Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API dynamicoverlay.cgi was vulnerable to a Denial-of-Service attack allowing for an attacker to block access to the ov…
|
NVD-CWE-noinfo
|
CVE-2023-21416
|
2024-11-8 18:15 |
2023-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2295
|
8.1 |
HIGH
Network
|
axis
|
axis_os_2022 axis_os_2018 axis_os_2020 axis_os axis_os_2016
|
Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API overlay_del.cgi is vulnerable to path traversal attacks that allows for file deletion. This flaw can only be explo…
|
CWE-22
Path Traversal
|
CVE-2023-21415
|
2024-11-8 18:15 |
2023-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2296
|
6.8 |
MEDIUM
Physics
|
axis
|
axis_os
|
NCC Group has found a flaw during the annual internal penetration test ordered by Axis Communications. The protection for device tampering (commonly known as Secure Boot) contains a flaw which provid…
|
NVD-CWE-noinfo
|
CVE-2023-21414
|
2024-11-8 18:15 |
2023-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2297
|
7.2 |
HIGH
Network
|
axis
|
axis_os
|
GoSecure on behalf of Genetec Inc. has found a flaw that allows for a remote code execution during the installation of ACAP applications on the Axis device. The application handling service in AXIS O…
|
CWE-77
Command Injection
|
CVE-2023-21413
|
2024-11-8 18:15 |
2023-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2298
|
8.8 |
HIGH
Network
|
axis
|
license_plate_verifier
|
User provided input is not sanitized on the AXIS License Plate Verifier specific “search.cgi” allowing for
SQL injections.
|
CWE-89
SQL Injection
|
CVE-2023-21412
|
2024-11-8 18:15 |
2023-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2299
|
8.8 |
HIGH
Network
|
axis
|
license_plate_verifier
|
User provided input is not sanitized in the “Settings > Access Control” configuration interface allowing for
arbitrary code execution.
|
NVD-CWE-noinfo
|
CVE-2023-21411
|
2024-11-8 18:15 |
2023-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2300
|
8.8 |
HIGH
Network
|
axis
|
license_plate_verifier
|
User provided input is not sanitized on the AXIS License Plate Verifier specific “api.cgi” allowing for
arbitrary code execution.
|
NVD-CWE-noinfo
|
CVE-2023-21410
|
2024-11-8 18:15 |
2023-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|