nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-6509 CVE-2024-6509
MEDIUM
Record summary
CVE-2024-6509 has a selected CVSS score of 6.5 (medium).
Description
Marinus Pfund, member of the AXIS OS Bug Bounty Program, has found the VAPIX API alwaysmulti.cgi was vulnerable for file globbing which could lead to resource exhaustion of the Axis device. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 10, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | 6.50.0 to < 6.50.5.19 | affected |
| 7.0.0 to < 8.40.59 | affected | ||
| 9.0.0 to < 9.80.78 | affected | ||
| 10.0.0 to < 10.12.249 | affected | ||
| 11.0.0 to < 11.11.93 | affected |
References
3axis.com
https://www.axis.com/dam/public/47/bf/2c/cve-2024-6509-en-US-448996.pdf axis.com
https://www.axis.com/dam/public/f6/c6/f5/cve-2024-6509-en-US-458043.pdf