Impact
The ACAP framework contains a Time-of-Check to Time-of-Use race condition, which could allow a user to gain higher privileges on an Axis OS device. If the device permits installation of unsigned ACAP applications and a malicious ACAP is installed, the attacker could execute privileged actions or compromise the device. The weakness is a concurrency bug that violates atomicity during permission checks.
Affected Systems
Axis Communications AB's AXIS OS is impacted. No specific version information is disclosed by the vendor, but the vulnerability exists in the ACAP framework used across multiple devices running AXIS OS. Any device configured to allow unsigned ACAP applications is vulnerable.
Risk and Exploitability
The CVSS score of 5.7 indicates medium severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a configuration that allows unsigned ACAP applications and a user to be persuaded to install a malicious ACAP. The likely attack vector is social engineering combined with misconfiguration, and it can be exploited locally once the device is configured to permit unsigned apps.
OpenCVE Enrichment