Axis Communications Ab Axis Os vulnerabilities
51 known vulnerabilities affecting axis_communications_ab/axis_os.
Total CVEs
51
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH18MEDIUM31LOW2
Vulnerabilities
Page 3 of 3
CVE-2025-6571P4MEDIUMCVSS 6.0≥ 12.0.0, < 12.6.66≥ 11.11.0, < 11.11.1692025-11-11
CVE-2025-6571 [MEDIUM] CWE-522 CVE-2025-6571: A 3rd-party component exposed its password in process arguments, allowing for low-privileged users t
A 3rd-party component exposed its password in process arguments, allowing for low-privileged users to access it.
nvd
CVE-2024-0066P4MEDIUMCVSS 5.3vAXIS OS 5.51 -11.92024-06-18
CVE-2024-0066 [MEDIUM] CWE-319 CVE-2024-0066: Johan Fagerström, member of the AXIS OS Bug Bounty Program, has found that a O3C feature may expose
Johan Fagerström, member of the AXIS OS Bug Bounty Program, has found that a O3C feature may expose sensitive traffic between the client (Axis device) and (O3C) server. If O3C is not being used this flaw does not apply.
Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information a
nvd
CVE-2023-21404P4MEDIUMCVSS 5.3vAXIS OS 11.0.X - 11.3.x2023-05-08
CVE-2023-21404 [MEDIUM] CWE-321 CVE-2023-21404: AXIS OS 11.0.X - 11.3.x use a static RSA key in legacy LUA-components to protect Axis-specific sourc
AXIS OS 11.0.X - 11.3.x use a static RSA key in legacy LUA-components to protect Axis-specific source code. The static RSA key is not used in any other secure communication nor can it be used to compromise the device or any customer data.
nvd
CVE-2025-0325P4MEDIUMCVSS 4.3≥ 6.50.0, < 6.50.5.21≥ 7.0.0, < 8.40.74+4 more2025-06-02
CVE-2025-0325 [MEDIUM] CWE-628 CVE-2025-0325: A Guard Tour VAPIX API parameter allowed the use of arbitrary values and can be incorrectly called,
A Guard Tour VAPIX API parameter allowed the use of arbitrary values and can be incorrectly called, allowing an attacker to block access to the guard tour configuration page in the web interface of the Axis device.
nvd
CVE-2025-0359P4MEDIUMCVSS 5.5≥ 11.11.0, < 11.11.135≥ 12.0.0, < 12.2.522025-03-04
CVE-2025-0359 [MEDIUM] CWE-863 CVE-2025-0359: During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a fl
During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the ACAP Application framework that allowed applications to access restricted D-Bus methods within the framework.
Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information
nvd
CVE-2024-8772P4MEDIUMCVSS 4.3≥ 9.80.0, < 9.80.84≥ 10.0.0, < 10.12.259+2 more2024-11-26
CVE-2024-8772 [MEDIUM] CWE-1286 CVE-2024-8772: 51l3nc3, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API managedoverlayimages
51l3nc3, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API managedoverlayimages.cgi was vulnerable to a race condition attack allowing for an attacker to block access to the overlay configuration page in the web interface of the Axis device. This flaw can only be exploited after authenticating with an operator- or administrator-p
nvd
CVE-2024-47261P4MEDIUMCVSS 4.3≥ 10.12.0, < 10.12.276≥ 11.0.0, < 11.11.141+1 more2025-04-08
CVE-2024-47261 [MEDIUM] CWE-1287 CVE-2024-47261: 51l3nc3, a member of the AXIS OS Bug Bounty Program, has found that the VAPIX API uploadoverlayimage
51l3nc3, a member of the AXIS OS Bug Bounty Program, has found that the VAPIX API uploadoverlayimage.cgi did not have sufficient input validation to allow an attacker to upload files to block access to create image overlays in the web interface of the Axis device.
nvd
CVE-2024-0067P4MEDIUMCVSS 4.3v8.40 - 11.102024-09-10
CVE-2024-0067 [MEDIUM] CWE-35 CVE-2024-0067: Marinus Pfund, member of the AXIS OS Bug Bounty Program, has found the VAPIX API ledlimit.cgi was v
Marinus Pfund, member of the AXIS OS Bug Bounty Program,
has found the VAPIX API ledlimit.cgi was vulnerable for path traversal attacks allowing to list folder/file names on the local file system of the Axis device.
Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and so
nvd
CVE-2025-9524P4MEDIUMCVSS 4.3≥ 6.50.0, < 6.50.5.21≥ 7.0.0, < 8.40.89+4 more2025-11-11
CVE-2025-9524 [MEDIUM] CWE-1287 CVE-2025-9524: The VAPIX API port.cgi did not have sufficient input validation, which may result in process crashes
The VAPIX API port.cgi did not have sufficient input validation, which may result in process crashes and impact usability. This vulnerability can only be exploited after authenticating with a viewer- operator- or administrator-privileged service account.
nvd
CVE-2025-8998P4LOWCVSS 3.1≥ 6.50.0, < 6.50.5.22≥ 7.0.0, < 8.40.90+4 more2025-11-11
CVE-2025-8998 [LOW] CWE-73 CVE-2025-8998: It was possible to upload files with a specific name to a temporary directory, which may result in p
It was possible to upload files with a specific name to a temporary directory, which may result in process crashes and impact usability. This flaw can only be exploited after authenticating with an operator- or administrator-privileged service account.
nvd
CVE-2024-8160P4LOWCVSS 2.7≥ 10.9.0, < 10.12.257≥ 12.0.0, < 12.1.212024-11-26
CVE-2024-8160 [LOW] CWE-1286 CVE-2024-8160: Erik de Jong, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API ftptest.cgi did
Erik de Jong, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API ftptest.cgi did not have a sufficient input validation allowing for a possible command injection leading to being able to transfer files from/to the Axis device. This flaw can only be exploited after authenticating with an administrator-privileged service account.
Axis
nvd
← Previous3 / 3