Vulnerabilidades em Axis Communications AB

84 resultados
Análise Vexday

Com 78 CVEs catalogadas, a Axis Communications AB apresenta um perfil de risco relativamente contido: nenhuma vulnerabilidade consta no catálogo CISA KEV de exploração ativa, taxa que fica abaixo da média geral do catálogo, e nenhum proof-of-concept público foi registrado. As três vulnerabilidades de severidade crítica merecem atenção prioritária, assim como as quatro surgidas nos últimos 90 dias, que indicam superfície de ataque em expansão recente. A CVE mais perigosa no momento, CVE-2023-21413, possui EPSS de 0,0125, sugerindo probabilidade de exploração ainda baixa no curto prazo, mas devendo ser monitorada. O tipo de falha mais frequente, CWE-1287 (validação imprópria de tipo de dado especificado), aponta para uma classe de defeito de implementação que, em dispositivos de rede como câmeras e encoders, pode ter implicações na integridade do processo de autenticação e controle de acesso.

CVE-2026-8158MEDIUMThe Signed Video Framework contained a  buffer overflow issue which could lead the application using this framework to crash. The issue excEPSS 0.2%CVE-2024-0066MEDIUMJohan Fagerström, member of the AXIS OS Bug Bounty Program, has found that a O3C feature may expose sensitive traffic between the client (AxEPSS 0.2%CVE-2025-12063MEDIUMAn insecure direct object reference allowed a non-admin user to modify or remove certain data objects without having the appropriate permissEPSS 0.2%CVE-2025-30025MEDIUMThe communication protocol used between the server process and the service control had a flaw that could lead to a local privilege escalatioEPSS 0.2%CVE-2026-5303MEDIUMThe ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege escalation. ThEPSS 0.2%CVE-2025-7622MEDIUMDuring an internal security assessment, a Server-Side Request Forgery (SSRF) vulnerability that allowed an authenticated attacker to access EPSS 0.2%CVE-2025-30027MEDIUMAn ACAP configuration file lacked sufficient input validation, which could allow for arbitrary code execution. This vulnerability can only bEPSS 0.2%CVE-2024-6831MEDIUMSeth Fogie, member of AXIS Camera Station Pro Bug Bounty Program has found that it is possible to edit and/or remove views without the necesEPSS 0.2%CVE-2025-11547HIGHAXIS Camera Station Pro contained a flaw to perform a privilege escalation attack on the server as a non-admin user.EPSS 0.2%CVE-2025-5454MEDIUMAn ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to potential privilege escaEPSS 0.2%CVE-2025-4645MEDIUMAn ACAP configuration file lacked sufficient input validation, which could allow for arbitrary code execution. This vulnerability can only bEPSS 0.1%CVE-2025-3892MEDIUMACAP applications can be executed with elevated privileges, potentially leading to privilege escalation. This vulnerability can only be explEPSS 0.1%CVE-2024-6749MEDIUMSeth Fogie, member of the AXIS Camera Station Pro Bug Bounty Program, has found that the Incident report feature may expose sensitive credenEPSS 0.1%CVE-2025-0360HIGHDuring an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration fraEPSS 0.1%CVE-2025-0359HIGHDuring an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the ACAP Application framework thaEPSS 0.1%CVE-2025-6298MEDIUMACAP applications can gain elevated privileges due to improper input validation, potentially leading to privilege escalation. This vulnerabiEPSS 0.1%CVE-2025-8108MEDIUMAn ACAP configuration file has improper permissions and lacks input validation, which could potentially lead to privilege escalation. This vEPSS 0.1%CVE-2026-0804MEDIUMAn ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to potential privilege escaEPSS 0.1%CVE-2024-6476MEDIUMGee-netics, member of the AXIS Camera Station Pro Bug Bounty Program has found that it is possible for a non-admin user to gain system priviEPSS 0.1%CVE-2025-10714HIGHAXIS Optimizer was vulnerable to an unquoted search path vulnerability, which could potentially lead to privilege escalation within MicrosofEPSS 0.1%