Impact
A VAPIX API parameter accepts user input without proper validation, enabling an attacker who can authenticate with an administrator‑privileged service account to execute arbitrary code and then elevate privileges on the system.
Affected Systems
Vulnerable installations are Axis Communications AB AXIS OS devices that expose the affected VAPIX API. No specific version range is provided, so all current Axis OS releases that implement the VAPIX API are considered potentially affected.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity vulnerability. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalog. Exploitation requires possession of an administrator‑level service account; therefore, attackers with such credentials can leverage the flaw to gain elevated privileges. The attack vector is inferred to be remote, via the web interface or API, given that the flaw resides in a network‑exposed API.
OpenCVE Enrichment