Seth Fogie, member of AXIS Camera Station Pro Bug Bounty Program has found that it is possible to edit and/or remove views without the necessary permission due to a client-side-only check.
Axis has released patched versions for the highlighted flaw. Please
refer to the Axis security advisory for more information and solution.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 26 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 26 Nov 2024 07:30:00 +0000

Type Values Removed Values Added
Description Seth Fogie, member of AXIS Camera Station Pro Bug Bounty Program has found that it is possible to edit and/or remove views without the necessary permission due to a client-side-only check. Axis has released patched versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.
Weaknesses CWE-602
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Axis

Published:

Updated: 2024-11-26T14:09:25.685Z

Reserved: 2024-07-17T11:19:49.788Z

Link: CVE-2024-6831

cve-icon Vulnrichment

Updated: 2024-11-26T14:04:02.389Z

cve-icon NVD

Status : Received

Published: 2024-11-26T08:15:07.747

Modified: 2024-11-26T08:15:07.747

Link: CVE-2024-6831

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.