Vulnerability index

Browse CVEs

86 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Axis Os 2024 HIGH 7.5
CVE-2024-6979

Amin Aliakbari, member of the AXIS OS Bug Bounty Program, has found a broken access control which would lead to less-privileged operator- and/or view…

Fix: 11.11.94+
Fix from $1,950 2024-09-10
Axis Os MEDIUM 6.5
CVE-2024-0055

Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX APIs mediaclip.cgi and playclip.cgi was vulnerable for file globbing…

Fix: 10.12.228 / 11.9.53+
Fix from $1,600 2024-03-19
M3024 Lve Firmware HIGH 8.8
CVE-2023-5677

Brandon Rothel from QED Secure Solutions and Sam Hanson of Dragos have found that the VAPIX API tcptest.cgi did not have a sufficient input validatio…

Fix: 5.51.7.7+
Fix from $1,950 2024-02-05
Axis Os HIGH 8.8
CVE-2023-5800

Vintage, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API create_overlay.cgi did not have a sufficient input validation allowin…

Fix: 9.80.55 / 10.12.220+
Fix from $1,950 2024-02-05
Axis Os MEDIUM 6.8
CVE-2023-5553

During internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device tampering (commonly known as S…

Fix: 10.12.213 / 11.7.57+
Fix from $1,600 2023-11-21
Axis Os HIGH 7.1
CVE-2023-21417

Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API manageoverlayimage.cgi was vulnerable to path traversal attacks…

Fix: 9.80.49 / 10.12.208+
Fix from $1,950 2023-11-21
Axis Os HIGH 7.1
CVE-2023-21418

Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API irissetup.cgi was vulnerable to path traversal attacks that allo…

Fix: 6.50.5.15 / 8.40.35+
Fix from $1,950 2023-11-21
Axis Os MEDIUM 6.5
CVE-2023-21416

Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API dynamicoverlay.cgi was vulnerable to a Denial-of-Service attack …

Fix: 10.12.213 / 11.7.57+
Fix from $1,600 2023-11-21
Axis Os HIGH 8.1
CVE-2023-21415

Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API overlay_del.cgi is vulnerable to path traversal attacks that all…

Fix: 6.50.5.2 / 6.50.5.14+
Fix from $1,950 2023-10-16
Axis Os HIGH 7.2
CVE-2023-21413

GoSecure on behalf of Genetec Inc. has found a flaw that allows for a remote code execution during the installation of ACAP applications on the Axis …

Fix: 10.12.199 / 11.6.94+
Fix from $1,950 2023-10-16
Axis Os MEDIUM 6.8
CVE-2023-21414

NCC Group has found a flaw during the annual internal penetration test ordered by Axis Communications. The protection for device tampering (commonly …

Fix: 10.12.206 / 11.6.94+
Fix from $1,600 2023-10-16
License Plate Verifier HIGH 8.8
CVE-2023-21411

User provided input is not sanitized in the “Settings > Access Control” configuration interface allowing for arbitrary code execution.

Fix: after 2.8.3
Fix from $1,950 2023-08-03
License Plate Verifier HIGH 8.8
CVE-2023-21412

User provided input is not sanitized on the AXIS License Plate Verifier specific “search.cgi” allowing for SQL injections.

Fix: after 2.8.3
Fix from $1,950 2023-08-03
License Plate Verifier CRITICAL 9.8
CVE-2023-21408

Due to insufficient file permissions, unprivileged users could gain access to unencrypted user credentials that are used in the integration interface…

Fix: after 2.8.3
Fix from $2,300 2023-08-03
License Plate Verifier CRITICAL 9.8
CVE-2023-21409

Due to insufficient file permissions, unprivileged users could gain access to unencrypted administrator credentials allowing the configuration of the…

Fix: after 2.8.3
Fix from $2,300 2023-08-03
License Plate Verifier HIGH 8.8
CVE-2023-21407

A broken access control was found allowing for privileged escalation of the operator account to gain administrator privileges.

Fix: after 2.8.3
Fix from $1,950 2023-08-03
License Plate Verifier HIGH 8.8
CVE-2023-21410

User provided input is not sanitized on the AXIS License Plate Verifier specific “api.cgi” allowing for arbitrary code execution.

Fix: after 2.8.3
Fix from $1,950 2023-08-03
A1001 Firmware HIGH 8.8
CVE-2023-21406

Ariel Harush and Roy Hodir from OTORIO have found a flaw in the AXIS A1001 when communicating over OSDP. A heap-based buffer overflow was found in th…

Fix: after 1.65.4
Fix from $1,950 2023-07-25
A1001 Firmware MEDIUM 6.5
CVE-2023-21405

Knud from Fraktal.fi has found a flaw in some Axis Network Door Controllers and Axis Network Intercoms when communicating over OSDP, highlighting tha…

Fix: after 11.6.16.0
Fix from $1,600 2023-07-25
Axis Os MEDIUM 5.3
CVE-2023-21404

AXIS OS 11.0.X - 11.3.x use a static RSA key in legacy LUA-components to protect Axis-specific source code. The static RSA key is not used in any oth…

Fix: 11.4.52+
Fix from $1,600 2023-05-08
207w Firmware MEDIUM 6.1
CVE-2023-22984

A Vulnerability was discovered in Axis 207W network camera. There is a reflected XSS vulnerability in the web administration portal, which allows an …

No fix yet
Fix from $1,600 2023-02-21
P1204 Firmware CRITICAL 9.8
CVE-2017-20049

A vulnerability, was found in legacy Axis devices such as P3225 and M3005. This affects an unknown part of the component CGI Script. The manipulation…

Fix: after 6.30.1.1
Fix from $2,300 2022-06-15
Ip Utility HIGH 7.8
CVE-2022-23410

AXIS IP Utility before 4.18.0 allows for remote code execution and local privilege escalation by the means of DLL hijacking. IPUtility.exe would atte…

Fix: 4.18.0+
Fix from $1,950 2022-02-14
Axis Os HIGH 8.8
CVE-2021-31988

A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to add the Carriage Return and Line Feed…

Fix: 6.50.5.5 / 8.40.4.3+
Fix from $1,950 2021-10-05
Axis Os HIGH 7.5
CVE-2021-31987

A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to bypass blocked network recipients.

Fix: 6.50.5.5 / 8.40.4.3+
Fix from $1,950 2021-10-05
Axis Os MEDIUM 6.8
CVE-2021-31986

User controlled parameters related to SMTP notifications are not correctly validated. This can lead to a buffer overflow resulting in crashes and dat…

Fix: 6.50.5.5 / 8.40.4.3+
Fix from $1,600 2021-10-05
Device Manager MEDIUM 5.3
CVE-2021-31989

A user with permission to log on to the machine hosting the AXIS Device Manager client could under certain conditions extract a memory dump from the …

Fix: after 5.16.063
Fix from $1,600 2021-08-25
A1001 Firmware CRITICAL 9.8
CVE-2018-10660EPSS 82%

An issue was discovered in multiple models of Axis IP Cameras. There is Shell Command Injection.

Fix: 1.65.0 / 1.65.1+
Fix from $2,300 2018-06-26
A1001 Firmware CRITICAL 9.8
CVE-2018-10661EPSS 87%

An issue was discovered in multiple models of Axis IP Cameras. There is a bypass of access control.

Fix: 1.65.0 / 1.65.1+
Fix from $2,300 2018-06-26
A1001 Firmware CRITICAL 9.8
CVE-2018-10662EPSS 80%

An issue was discovered in multiple models of Axis IP Cameras. There is an Exposed Insecure Interface.

Fix: 1.65.0 / 1.65.1+
Fix from $2,300 2018-06-26