Gee-netics, member of the AXIS Camera Station Pro Bug Bounty Program has found that it is possible for a non-admin user to gain system privileges by redirecting a file deletion upon service restart.
Axis has released patched versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.
Metrics
Affected Vendors & Products
References
History
Tue, 26 Nov 2024 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 26 Nov 2024 07:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Gee-netics, member of the AXIS Camera Station Pro Bug Bounty Program has found that it is possible for a non-admin user to gain system privileges by redirecting a file deletion upon service restart. Axis has released patched versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution. | |
Weaknesses | CWE-276 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Axis
Published: 2024-11-26T07:00:46.615Z
Updated: 2024-11-26T14:09:25.935Z
Reserved: 2024-07-03T13:20:56.227Z
Link: CVE-2024-6476
Vulnrichment
Updated: 2024-11-26T14:04:13.853Z
NVD
Status : Received
Published: 2024-11-26T07:15:05.697
Modified: 2024-11-26T07:15:05.697
Link: CVE-2024-6476
Redhat
No data.