Axis Os 2022
Vendor:
First CVE: Oct 16, 2023 · Active for 2 years
9
Total CVEs
More Total CVEs than 86% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 28% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Axis Os 2022 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 16, 2023
2 years ago
Most Recent CVE
Apr 8, 2025
473 days ago
CVE Severity & Scoring
Axis Os 20229 CVEs
11%
44%
44%
All CVEs352,708 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network8 (88.9%)
Unknown0 (0.0%)
Physical1 (11.1%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low7 (77.8%)
High1 (11.1%)
None1 (11.1%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-5800HIGH Vintage,
member of the AXIS OS Bug Bounty Program, has found that the VAPIX API create_overlay.cgi
did not have a sufficient input validation allowing for a possible remote code
ex | Feb 5, 2024 | 8.8 | 28 | NO | NO |
CVE-2023-21415HIGH Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API overlay_del.cgi is vulnerable to path traversal attacks that allows for file deletion. This fla | Oct 16, 2023 | 8.1 | 22 | NO | NO |
CVE-2023-5553MEDIUM During internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device tampering (commonly known as Secure Boot) in AXIS OS making i | Nov 21, 2023 | 6.8 | 21 | NO | NO |
CVE-2024-0055MEDIUM Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX APIs mediaclip.cgi and playclip.cgi was vulnerable for file globbing which could lead to a resource | Mar 19, 2024 | 6.5 | 20 | NO | NO |
CVE-2023-21417HIGH Sandro Poppi, member of the AXIS OS Bug Bounty Program,
has found that the VAPIX API manageoverlayimage.cgi was vulnerable to path traversal attacks that allows for file/folder de | Nov 21, 2023 | 7.1 | 20 | NO | NO |
CVE-2023-21416MEDIUM Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API dynamicoverlay.cgi was vulnerable to a Denial-of-Service attack allowing for an attacker to blo | Nov 21, 2023 | 6.5 | 19 | NO | NO |
CVE-2023-21418HIGH Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API irissetup.cgi was vulnerable to path traversal attacks that allows for file deletion. This flaw | Nov 21, 2023 | 7.1 | 18 | NO | NO |
CVE-2024-47261MEDIUM 51l3nc3, a member of the AXIS OS Bug Bounty Program, has found that the VAPIX API uploadoverlayimage.cgi did not have sufficient input validation to allow an attacker to upload fil | Apr 8, 2025 | 4.3 | 16 | NO | NO |
Erik de Jong, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API ftptest.cgi did not have a sufficient input validation allowing for a possible command injectio | Nov 26, 2024 | 2.7 | 13 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Axis Os 2022
Top CWEs
Versions
No cataloged versions.