CVE-2024-8772 is a race condition vulnerability in the VAPIX API managedoverlayimages.cgi of Axis OS, allowing an authenticated attacker to block access to the overlay configuration page. This flaw affects Axis devices running vulnerable AXIS OS versions. With a CVSS score of 4.3 (Medium), the attack requires low privileges and network access, but its impact is limited to denial of availability for a specific configuration page. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage. Axis has released patched versions to address this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Axis Communications AB | AXIS OS | >= 10.0.0, < 10.12.259, >= 11.0.0, < 11.11.118, >= 12.0.0, < 12.1.28, >= 9.80.0, < 9.80.84CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.