CVE-2024-47261 is a medium-severity vulnerability affecting Axis OS, Axis OS 2022, and Axis OS 2024. The VAPIX API uploadoverlayimage.cgi lacks sufficient input validation, allowing an authenticated attacker to upload files that can block the creation of image overlays in the web interface. With a CVSS score of 4.3, this vulnerability has a low impact, primarily affecting availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.12.0, < 12.3.56CPE matchmatch criteria | cpe:2.3:o:axis:axis_os:*:*:*:*:active:*:*:* | ||
< 10.12.276CPE matchmatch criteria | cpe:2.3:o:axis:axis_os_2022:*:*:*:*:lts:*:*:* | ||
< 11.11.141CPE matchmatch criteria | cpe:2.3:o:axis:axis_os_2024:*:*:*:*:lts:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.