Vulnerabilidades em Axis Communications AB

84 resultados
Análise Vexday

Com 78 CVEs catalogadas, a Axis Communications AB apresenta um perfil de risco relativamente contido: nenhuma vulnerabilidade consta no catálogo CISA KEV de exploração ativa, taxa que fica abaixo da média geral do catálogo, e nenhum proof-of-concept público foi registrado. As três vulnerabilidades de severidade crítica merecem atenção prioritária, assim como as quatro surgidas nos últimos 90 dias, que indicam superfície de ataque em expansão recente. A CVE mais perigosa no momento, CVE-2023-21413, possui EPSS de 0,0125, sugerindo probabilidade de exploração ainda baixa no curto prazo, mas devendo ser monitorada. O tipo de falha mais frequente, CWE-1287 (validação imprópria de tipo de dado especificado), aponta para uma classe de defeito de implementação que, em dispositivos de rede como câmeras e encoders, pode ter implicações na integridade do processo de autenticação e controle de acesso.

CVE-2023-5553HIGHDuring internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device tampering (commonly kEPSS 0.3%CVE-2025-0361MEDIUMDuring an annual penetration test conducted on behalf of Axis Communications, Truesec discovered a flaw in the VAPIX Device Configuration frEPSS 0.3%CVE-2023-21406HIGHHeap-based buffer overflow in Axis A1001 Network Door Controller's OSDP communicationEPSS 0.3%CVE-2024-6979MEDIUMAmin Aliakbari, member of the AXIS OS Bug Bounty Program, has found a broken access control which would lead to less-privileged operator- anEPSS 0.3%CVE-2023-21405MEDIUMDenial-of-Service vulnerability in Axis Network Door Controller's and Axis Network Intercom's OSDP communicationEPSS 0.3%CVE-2026-6181MEDIUMThe Device Configuration Framework is vulnerable to an authentication bypass flaw. This flaw can only be exploited after authenticating withEPSS 0.3%CVE-2025-5452MEDIUMA malicious ACAP application can gain access to admin-level service account credentials used by legitimate ACAP applications, leading to potEPSS 0.3%CVE-2023-21404MEDIUMAXIS OS 11.0.X - 11.3.x use a static RSA key in legacy LUA-components to protect Axis-specific source code. The static RSA key is not used iEPSS 0.3%CVE-2025-12757MEDIUMAn AXIS Camera Station Pro feature can be exploited in a way that allows a non-admin user to view information they are not permitted to.EPSS 0.3%CVE-2025-9524MEDIUMThe VAPIX API port.cgi did not have sufficient input validation, which may result in process crashes and impact usability. This vulnerabilitEPSS 0.3%CVE-2025-0358HIGHDuring an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration fraEPSS 0.2%CVE-2024-7784MEDIUMDuring internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device tampering (commonly kEPSS 0.2%CVE-2025-1056MEDIUMGee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has identified an issue with a specific file that the server is using. A nEPSS 0.2%CVE-2025-13064MEDIUMA server-side injection was possible for a malicious admin to manipulate the application to include a malicious script which is executed by EPSS 0.2%CVE-2023-21414HIGHNCC Group has found a flaw during the annual internal penetration test ordered by Axis Communications. The protection for device tampering (EPSS 0.2%CVE-2026-5304MEDIUMAn ACAP configuration file lacks input validation, which could potentially lead to privilege escalation. This vulnerability can only be explEPSS 0.2%CVE-2025-0926MEDIUMGee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has found that it is possible for a non-admin user to remove system files EPSS 0.2%CVE-2024-7696MEDIUMSeth Fogie, member of AXIS Camera Station Pro Bug Bounty Program, has found that it is possible for an authenticated malicious client to tamEPSS 0.2%CVE-2026-1185MEDIUMA configuration file on the local file system had improper input validation which could allow code execution and potentially lead to privileEPSS 0.2%CVE-2025-8998LOWIt was possible to upload files with a specific name to a temporary directory, which may result in process crashes and impact usability. ThiEPSS 0.2%