A configuration file on the local file system had improper input validation which could allow code execution and potentially lead to privilege escala…
ACAP applications can gain elevated privileges due to improper input validation during the installation process, potentially leading to privilege esc…
An ACAP configuration file lacked sufficient input validation, which could allow command injection and potentially lead to privilege escalation. This…
An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to potential privilege escalation. T…
An insecure direct object reference allowed a non-admin user to modify or remove certain data objects without having the appropriate permissions.
AXIS Camera Station Pro contained a flaw to perform a privilege escalation attack on the server as a non-admin user.
The VAPIX API mediaclip.cgi that did not have a sufficient input validation allowing for a possible remote code execution. This flaw can only be expl…
An ACAP configuration file has improper permissions and lacks input validation, which could potentially lead to privilege escalation. This vulnerabil…
The ACAP Application framework could allow privilege escalation through a symlink attack. This vulnerability can only be exploited if the Axis device…
ACAP applications can gain elevated privileges due to improper input validation, potentially leading to privilege escalation. This vulnerability can …
An ACAP configuration file has improper permissions, which could allow command injection and potentially lead to privilege escalation. This vulnerabi…
An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to potential privilege escalation. T…
A malicious ACAP application can gain access to admin-level service account credentials used by legitimate ACAP applications, leading to potential pr…
An ACAP configuration file lacked sufficient input validation, which could allow for arbitrary code execution. This vulnerability can only be exploit…
ACAP applications can be executed with elevated privileges, potentially leading to privilege escalation. This vulnerability can only be exploited if …
An ACAP configuration file lacked sufficient input validation, which could allow for arbitrary code execution. This vulnerability can only be exploit…
During an internal security assessment, a Server-Side Request Forgery (SSRF) vulnerability that allowed an authenticated attacker to access internal …
The AXIS Camera Station Server had a flaw that allowed to bypass authentication that is normally required.
The communication protocol used between client and server had a flaw that could lead to an authenticated user performing a remote code execution atta…
The communication protocol used between the server process and the service control had a flaw that could lead to a local privilege escalation.
The communication protocol used between client and server had a flaw that could be leveraged to execute a man in the middle attack.
The VAPIX Device Configuration framework allowed a privilege escalation, enabling a lower-privileged user to gain administrator privileges.
During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework th…
Gee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has identified an issue with a specific file that the server is using. A non-admin …
Gee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has found that it is possible for a non-admin user to remove system files causing a…
During an annual penetration test conducted on behalf of Axis Communications, Truesec discovered a flaw in the VAPIX Device Configuration framework t…
During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework th…
During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the ACAP Application framework that allowed…
Girishunawane, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API dynamicoverlay.cgi did not have a sufficient input validation a…
Seth Fogie, member of AXIS Camera Station Pro Bug Bounty Program, has found that it is possible for an authenticated malicious client to tamper with …