Axis AXIS OS
cpe:2.3:o:axis:axis_os:*:*:*:*:*:*:*
- >= 12.0, <= 12.3
A privilege escalation vulnerability has been identified in the VAPIX Device Configuration framework of Axis products running AXIS OS versions 12.0 through 12.3. This vulnerability allows a lower-privileged user to gain administrator rights. The issue was discovered during a penetration test conducted for Axis Communications by Truesec.
Exploitation of this vulnerability allows lower-privileged users to gain administrator privileges on the affected device.
Axis has released a patch for this vulnerability in AXIS OS Active Track 12.4.0. Devices not included in this track but still under support will receive a patch according to their planned maintenance and release schedule. Users are advised to update their Axis device software to the latest version available.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.