- Description
- Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX APIs mediaclip.cgi and playclip.cgi was vulnerable for file globbing which could lead to a resource exhaustion attack. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.
- Source
- product-security@axis.com
- NVD status
- Analyzed
- Products
- axis_os, axis_os_2022
CVSS 3.1
- Type
- Secondary
- Base score
- 6.5
- Impact score
- 3.6
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Severity
- MEDIUM
- product-security@axis.com
- CWE-155
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:axis:axis_os:*:*:*:*:active:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E8327A35-1BDD-439D-881B-3BBC4DC016BF",
"versionEndExcluding": "11.9.53",
"versionStartIncluding": "10.12.0"
},
{
"criteria": "cpe:2.3:o:axis:axis_os_2022:*:*:*:*:lts:*:*:*",
"vulnerable": true,
"matchCriteriaId": "47672541-95F0-42A9-A012-2BCD07FE585E",
"versionEndExcluding": "10.12.228"
}
],
"operator": "OR"
}
]
}
]