Axis Communications AXIS OS
cpe:2.3:o:axis:axis_os:*:*:*:*:*:*:*
- >= 12.0.0, <= 12.10.36
A vulnerability in Axis Communications AXIS OS versions 12.0.0 through 12.10.36 allows for privilege escalation and code execution. This issue arises from improper input validation in a configuration file on the local file system. The vulnerability can only be exploited by an attacker with SSH access to the device.
Exploitation of this vulnerability could lead to unauthorized code execution and privilege escalation on the affected Axis device.
Axis has released a patch for this vulnerability in AXIS OS Active Track 12.10.37. For devices not included in this track but still under support, patches will be provided according to the planned maintenance and release schedule. Users are advised to update their Axis device software to the latest version available.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.