AXIS OS Vulnerability: A New Threat to Secure Boot
CVE-2024-7784
6.1MEDIUM
Key Information:
- Vendor
- Axis Communications Ab
- Status
- Axis Os
- Vendor
- CVE Published:
- 10 September 2024
Summary
A vulnerability has been identified in the Secure Boot mechanism of Axis OS, which ensures the integrity of the device during startup. This flaw could allow an attacker to bypass the tamper protection features, potentially affecting the security posture of devices utilizing the affected OS versions. Axis Communications has acknowledged the issue and has released patched versions of Axis OS to remedy the situation. Users are encouraged to upgrade to the latest versions as outlined in the Axis security advisory to mitigate risks associated with this vulnerability.
Affected Version(s)
AXIS OS ARTPEC 8 10.9 - 11.11
AXIS OS i.MX6 SX 10.10 - 11.11
AXIS OS i.MX8 QP 11.11
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved