Axis OS Vulnerability Could Lead to Command Injection and File Transfer
CVE-2024-8160
What is CVE-2024-8160?
Erik de Jong, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API ftptest.cgi did not have a sufficient input validation allowing for a possible command injection leading to being able to transfer files from/to the Axis device. This flaw can only be exploited after authenticating with an administrator-privileged service account. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
AXIS OS 10.9.0 < 10.12.257
AXIS OS 12.0.0 < 12.1.21
AXIS OS 11.0.0 < 11.11.116
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
