nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-0055 CVE-2024-0055
MEDIUM
Record summary
CVE-2024-0055 has a selected CVSS score of 6.5 (medium).
Description
Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX APIs mediaclip.cgi and playclip.cgi was vulnerable for file globbing which could lead to a resource exhaustion attack. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 19, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | AXIS OS 10.12 - 11.8 | affected |
References
2axis.com
https://www.axis.com/dam/public/c4/00/c5/cve-2024-0055-en-US-432117.pdf