Show filters
274 Total Results
Displaying 11-20 of 274
Sort by:
Attacker Value
Unknown
CVE-2024-52545
Disclosure Date: December 03, 2024 (last updated December 21, 2024)
An unauthenticated attacker can perform an out of bounds heap read in the IQ Service (TCP port 9876). This vulnerability has been resolved in firmware version 2.800.0000000.8.R.20241111.
0
Attacker Value
Unknown
CVE-2024-52544
Disclosure Date: December 03, 2024 (last updated December 21, 2024)
An unauthenticated attacker can trigger a stack based buffer overflow in the DP Service (TCP port 3500). This vulnerability has been resolved in firmware version 2.800.0000000.8.R.20241111.
0
Attacker Value
Unknown
CVE-2024-6831
Disclosure Date: November 26, 2024 (last updated January 05, 2025)
Seth Fogie, member of AXIS Camera Station Pro Bug Bounty Program has found that it is possible to edit and/or remove views without the necessary permission due to a client-side-only check.
Axis has released patched versions for the highlighted flaw. Please
refer to the Axis security advisory for more information and solution.
0
Attacker Value
Unknown
CVE-2024-47257
Disclosure Date: November 26, 2024 (last updated December 21, 2024)
Florent Thiéry has found that selected Axis devices were vulnerable to handling certain ethernet frames which could lead to the Axis device becoming unavailable in the network.
Axis has released patched AXIS OS versions for the highlighted flaw for products that are still under AXIS OS software support. Please refer to the Axis security advisory for more information and solution.
0
Attacker Value
Unknown
CVE-2024-6749
Disclosure Date: November 26, 2024 (last updated January 05, 2025)
Seth Fogie, member of the AXIS Camera Station Pro Bug Bounty Program, has found that the Incident report feature may expose sensitive credentials on the AXIS Camera Station windows client. If Incident report is not being used with credentials configured this flaw does not apply.
Axis has released patched versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.
0
Attacker Value
Unknown
CVE-2024-6476
Disclosure Date: November 26, 2024 (last updated January 05, 2025)
Gee-netics, member of the AXIS Camera Station Pro Bug Bounty Program has found that it is possible for a non-admin user to gain system privileges by redirecting a file deletion upon service restart.
Axis has released patched versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.
0
Attacker Value
Unknown
CVE-2024-11136
Disclosure Date: November 14, 2024 (last updated November 15, 2024)
The default TCL Camera application exposes a provider vulnerable to path traversal vulnerability. Malicious application can supply malicious URI path and delete arbitrary files from user’s external storage.
0
Attacker Value
Unknown
CVE-2024-45253
Disclosure Date: November 14, 2024 (last updated November 14, 2024)
Avigilon – CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
0
Attacker Value
Unknown
CVE-2024-47790
Disclosure Date: October 04, 2024 (last updated October 14, 2024)
** UNSUPPORTED WHEN ASSIGNED ** This vulnerability exists in D3D Security IP Camera D8801 due to usage of insecure Real-Time Streaming Protocol (RTSP) version for live video streaming. A remote attacker could exploit this vulnerability by crafting a RTSP packet leading to unauthorized access to live feed of the targeted device. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
0
Attacker Value
Unknown
CVE-2024-47789
Disclosure Date: October 04, 2024 (last updated October 14, 2024)
** UNSUPPORTED WHEN ASSIGNED ** This vulnerability exists in D3D Security IP Camera D8801 due to usage of weak authentication scheme of the HTTP header protocol where authorization tag contain a Base-64 encoded username and password. A remote attacker could exploit this vulnerability by crafting a HTTP packet leading to exposure of user credentials of the targeted device. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
0