- Description
- During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the ACAP Application framework that allowed applications to access restricted D-Bus methods within the framework. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.
- Source
- product-security@axis.com
- NVD status
- Analyzed
- Products
- axis_os, axis_os_2024
CVSS 3.1
- Type
- Primary
- Base score
- 5.5
- Impact score
- 3.6
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Severity
- MEDIUM
- product-security@axis.com
- CWE-863
- Hype score
- Not currently trending
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:axis:axis_os:*:*:*:*:active:*:*:*",
"matchCriteriaId": "4CE29EC9-EB6F-44EF-ACBB-A484B7D8E7E6",
"versionEndExcluding": "12.2.52",
"versionStartIncluding": "11.11.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:axis:axis_os_2024:*:*:*:*:lts:*:*:*",
"matchCriteriaId": "A3ACD321-ABF7-46AE-A389-E8FD76EF0C51",
"versionEndExcluding": "11.11.135",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]