CVE-2024-7784
published 2024-09-10CVE-2024-7784: During internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device tampering (commonly known as Secure…
PriorityP429medium6.1CVSS 3.1
AVPACLPRNUINSUCHIHAN
EPSS
0.24%
14.8th percentile
During internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device tampering (commonly known as Secure Boot) in AXIS OS making it vulnerable to a sophisticated attack to bypass this protection. To Axis' knowledge, there are no known exploits of the vulnerability at this time. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| axis_communications_ab | axis_os | >= 10.10.0 < 10.12.247 | 10.12.247 |
| axis_communications_ab | axis_os | >= 10.9.0 < 10.12.246 | 10.12.246 |
| axis_communications_ab | axis_os | >= 11.0.0 < 11.11.80 | 11.11.80 |
| axis_communications_ab | axis_os | >= 11.0.0 < 11.11.85 | 11.11.85 |
| axis_communications_ab | axis_os | >= 11.11.0 < 11.11.80 | 11.11.80 |
| axis_communications_ab | axis_os | >= 11.8.0 < 11.11.85 | 11.11.85 |
| axis_communications_ab | axis_os | >= 12.0.0 < 12.0.40 | 12.0.40 |
| axis_communications_ab | axis_os | >= 12.0.0 < 12.0.47 | 12.0.47 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-09-10
Published