CVE-2024-7784 is a medium-severity vulnerability affecting AXIS OS, where a flaw in the device tampering protection (Secure Boot) could be bypassed by a sophisticated attack. This vulnerability has a CVSS score of 6.1, indicating a physical attack vector with low complexity, requiring no user interaction, and potentially leading to high confidentiality and integrity impacts. Axis has released patched versions of AXIS OS to address this issue. Currently, there are no known exploits in the wild, no public exploit code available, and minimal community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Axis Communications AB | AXIS OS | >= 10.9.0, < 10.12.246, >= 11.0.0, < 11.11.80, >= 12.0.0, < 12.0.40CNA affecteddefault unaffected | |
| Axis Communications AB | AXIS OS | >= 10.10.0, < 10.12.247, >= 11.0.0, < 11.11.85, >= 12.0.0, < 12.0.47CNA affecteddefault unaffected | |
| Axis Communications AB | AXIS OS | >= 11.11.0, < 11.11.80, >= 12.0.0, < 12.0.47CNA affecteddefault unaffected | |
| Axis Communications AB | AXIS OS | >= 11.8.0, < 11.11.85, >= 12.0.0, < 12.0.47CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.