Axis Communications Ab Axis Os vulnerabilities
51 known vulnerabilities affecting axis_communications_ab/axis_os.
Total CVEs
51
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH18MEDIUM31LOW2
Vulnerabilities
Page 2 of 3
CVE-2023-21416P3MEDIUMCVSS 6.5vAXIS OS 10.7 – 11.62023-11-21
CVE-2023-21416 [MEDIUM] CWE-35 CVE-2023-21416: Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API dynamicoverlay.
Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API dynamicoverlay.cgi was vulnerable to a Denial-of-Service attack allowing for an attacker to block access to the overlay configuration page in the web interface of the Axis device. This flaw can only be exploited after authenticating with an operator- or administrator
nvd
CVE-2024-6509P3MEDIUMCVSS 6.5≥ 6.50.0, < 6.50.5.19≥ 7.0.0, < 8.40.59+3 more2024-09-10
CVE-2024-6509 [MEDIUM] CWE-155 CVE-2024-6509: Marinus Pfund, member of the AXIS OS Bug Bounty Program, has found the VAPIX API alwaysmulti.cgi wa
Marinus Pfund, member of the AXIS OS Bug Bounty Program,
has found the VAPIX API alwaysmulti.cgi was vulnerable for file globbing which could lead to resource exhaustion of the Axis device.
Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.
nvd
CVE-2025-6779P3MEDIUMCVSS 6.7≥ 12.0.0, < 12.6.402025-11-11
CVE-2025-6779 [MEDIUM] CWE-732 CVE-2025-6779: An ACAP configuration file has improper permissions, which could allow command injection and potenti
An ACAP configuration file has improper permissions, which could allow command injection and potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.
nvd
CVE-2025-5718P3MEDIUMCVSS 6.8≥ 12.0.0, < 12.6.302025-11-11
CVE-2025-5718 [MEDIUM] CWE-59 CVE-2025-5718: The ACAP Application framework could allow privilege escalation through a symlink attack. This vulne
The ACAP Application framework could allow privilege escalation through a symlink attack. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.
nvd
CVE-2024-0055P3MEDIUMCVSS 6.5vAXIS OS 10.12 - 11.82024-03-19
CVE-2024-0055 [MEDIUM] CWE-155 CVE-2024-0055: Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX APIs mediaclip.cgi
Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX APIs mediaclip.cgi and playclip.cgi was vulnerable for file globbing which could lead to a resource exhaustion attack. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.
nvd
CVE-2024-0054P3MEDIUMCVSS 6.5vAXIS OS 6.50 - 11.82024-03-19
CVE-2024-0054 [MEDIUM] CWE-155 CVE-2024-0054: Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX APIs local_list.cgi
Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX APIs local_list.cgi, create_overlay.cgi and irissetup.cgi was vulnerable for file globbing which could lead to a resource exhaustion attack. Axis has released patched AXIS OS
versions for the highlighted flaw. Please refer to the Axis security advisory
for more informatio
nvd
CVE-2025-4645P4MEDIUMCVSS 6.7≥ 12.0.0., < 12.6.72025-11-11
CVE-2025-4645 [MEDIUM] CWE-1287 CVE-2025-4645: An ACAP configuration file lacked sufficient input validation, which could allow for arbitrary code
An ACAP configuration file lacked sufficient input validation, which could allow for arbitrary code execution. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.
nvd
CVE-2024-47260P3MEDIUMCVSS 6.5≥ 9.80.0, < 9.80.89≥ 10.0.0, < 10.12.270+2 more2025-03-04
CVE-2024-47260 [MEDIUM] CWE-641 CVE-2024-47260: 51l3nc3, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API mediaclip.cgi did no
51l3nc3, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API mediaclip.cgi did not have a sufficient input validation allowing for uploading more audio clips then designed resulting in the Axis device running out of memory.
Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advis
nvd
CVE-2025-30027P4MEDIUMCVSS 6.7≥ 12.0.0, < 12.3.362025-08-12
CVE-2025-30027 [MEDIUM] CWE-1287 CVE-2025-30027: An ACAP configuration file lacked sufficient input validation, which could allow for arbitrary code
An ACAP configuration file lacked sufficient input validation, which could allow for arbitrary code execution. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.
nvd
CVE-2025-5454P4MEDIUMCVSS 6.7≥ 12.0.0, < 12.6.182025-11-11
CVE-2025-5454 [MEDIUM] CWE-35 CVE-2025-5454: An ACAP configuration file lacked sufficient input validation, which could allow a path traversal at
An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to potential privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP applica
nvd
CVE-2025-8108P4MEDIUMCVSS 6.7≥ 12.0.0, < 12.7.332025-11-11
CVE-2025-8108 [MEDIUM] CWE-732 CVE-2025-8108: An ACAP configuration file has improper permissions and lacks input validation, which could potentia
An ACAP configuration file has improper permissions and lacks input validation, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.
nvd
CVE-2025-3892P4MEDIUMCVSS 6.7≥ 12.0.0, < 12.5.312025-08-12
CVE-2025-3892 [MEDIUM] CWE-250 CVE-2025-3892: ACAP applications can be executed with elevated privileges, potentially leading to privilege escalat
ACAP applications can be executed with elevated privileges, potentially leading to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.
nvd
CVE-2025-6298P4MEDIUMCVSS 6.7≥ 12.0.0, < 12.6.282025-11-11
CVE-2025-6298 [MEDIUM] CWE-1287 CVE-2025-6298: ACAP applications can gain elevated privileges due to improper input validation, potentially leading
ACAP applications can gain elevated privileges due to improper input validation, potentially leading to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.
nvd
CVE-2025-9055P4MEDIUMCVSS 6.4≥ 12.0.0, < 12.7.312025-11-11
CVE-2025-9055 [MEDIUM] CWE-250 CVE-2025-9055: The VAPIX Edge storage API that allowed a privilege escalation, enabling a VAPIX administrator-privi
The VAPIX Edge storage API that allowed a privilege escalation, enabling a VAPIX administrator-privileged user to gain Linux Root privileges. This flaw can only be exploited after authenticating with an administrator-privileged service account.
nvd
CVE-2024-47262P4MEDIUMCVSS 5.3≥ 6.50.0, < 6.50.5.19≥ 7.0.0, < 8.40.66+4 more2025-03-04
CVE-2024-47262 [MEDIUM] CWE-1287 CVE-2024-47262: Dzmitry Lukyanenka, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API param.cgi
Dzmitry Lukyanenka, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API param.cgi was vulnerable to a race condition attack allowing for an attacker to block access to the web interface of the Axis device. Other API endpoints or services not making use of param.cgi are not affected.
Axis has released patched AXIS OS versions for
nvd
CVE-2025-0361P4MEDIUMCVSS 5.3≥ 11.11.0, < 11.11.141≥ 12.0.0, < 12.3.562025-04-08
CVE-2025-0361 [MEDIUM] CWE-203 CVE-2025-0361: During an annual penetration test conducted on behalf of Axis Communications, Truesec discovered a f
During an annual penetration test conducted on behalf of Axis Communications, Truesec discovered a flaw in the VAPIX Device Configuration framework that allowed for unauthenticated username enumeration through the VAPIX Device Configuration SSH Management API.
nvd
CVE-2021-31986P4MEDIUMCVSS 6.8vAXIS OS 6.40 or later2021-10-05
CVE-2021-31986 [MEDIUM] CWE-122 CVE-2021-31986: User controlled parameters related to SMTP notifications are not correctly validated. This can lead
User controlled parameters related to SMTP notifications are not correctly validated. This can lead to a buffer overflow resulting in crashes and data leakage.
nvd
CVE-2023-5553P4MEDIUMCVSS 6.8vAXIS OS 10.8 - 11.62023-11-21
CVE-2023-5553 [MEDIUM] CWE-863 CVE-2023-5553: During internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the pro
During internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device tampering (commonly known as Secure Boot) in AXIS OS making it vulnerable to a sophisticated attack to bypass this protection. To Axis' knowledge, there are no known exploits of the vulnerability at this time. Axis has released patche
nvd
CVE-2023-21414P4MEDIUMCVSS 6.8vAXIS OS 10.11 - 11.52023-10-16
CVE-2023-21414 [MEDIUM] CWE-121 CVE-2023-21414: NCC Group has found a flaw during the annual internal penetration test ordered by Axis Communication
NCC Group has found a flaw during the annual internal penetration test ordered by Axis Communications. The protection for device tampering (commonly known as Secure Boot) contains a flaw which provides an opportunity for a sophisticated attack to bypass this protection. Axis has released patched AXIS OS versions for the highlighted flaw. Please refe
nvd
CVE-2024-7784P4MEDIUMCVSS 6.1≥ 10.9.0, < 10.12.246≥ 11.0.0, < 11.11.80+6 more2024-09-10
CVE-2024-7784 [MEDIUM] CWE-121 CVE-2024-7784: During internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the pro
During internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device tampering (commonly known as Secure Boot) in AXIS OS making it vulnerable to a sophisticated attack to bypass this protection. To Axis' knowledge, there are no known exploits of the vulnerability at this time. Axis has released patche
nvd