Axis AXIS Device Manager
cpe:2.3:a:axis:device_manager:*:*:*:*:*:*:*
- < 5.32
A vulnerability in the communication protocol between client and server in AXIS Device Manager versions prior to 5.32 allows for a man-in-the-middle attack. This flaw arises from improper certificate validation, which could be exploited to intercept or alter communications between the client and server.
Exploitation of this vulnerability allows for a man-in-the-middle attack, where an attacker could intercept, modify, or inject communications between the client and server.
Users are advised to update AXIS Device Manager to version 5.32, where this vulnerability has been addressed. The latest versions can be found on the Axis vulnerability management portal.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.