cve/2024/CVE-2024-0054.md
2024-05-25 21:48:12 +02:00

854 B

CVE-2024-0054

Description

Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX APIs local_list.cgi, create_overlay.cgi and irissetup.cgi was vulnerable for file globbing which could lead to a resource exhaustion attack. Axis has released patched AXIS OSversions for the highlighted flaw. Please refer to the Axis security advisoryfor more information and solution.

POC

Reference

No PoCs from references.

Github