CVE-2024-0067

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/09/2024
Last modified:
08/11/2024

Description

Marinus Pfund, member of the AXIS OS Bug Bounty Program, <br /> has found the VAPIX API ledlimit.cgi was vulnerable for path traversal attacks allowing to list folder/file names on the local file system of the Axis device. <br /> Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.