Impact
The ACAP framework in Axis OS contains a Time‑of‑Check to Time‑of‑Use (TOCTOU) race condition that may allow an attacker to elevate privileges. This weakness can be exploited only if the device is configured to permit installation of unsigned ACAP applications and an attacker succeeds in convincing the user to install a malicious ACAP module. If executed, the attacker could gain elevated rights on the device, potentially compromising its confidentiality, integrity or availability.
Affected Systems
Axis Communications AB Axis OS devices that allow unsigned ACAP installations are impacted. No specific version information is given, so any device with the default or custom configuration permitting unsigned ACAPs should be assessed.
Risk and Exploitability
The vulnerability is scored ‑ CVSS 5.1, which indicates moderate risk. EPSS is unavailable, and the issue is not listed in the CISA KEV catalog. The likely attack vector is social engineering or other means to persuade a user to install a malicious unsigned ACAP, after which the TOCTOU race condition could be triggered to gain higher privileges. No further exploitation prerequisites are described, so the threat remains confined to devices configured to accept unsigned ACAP applications.
OpenCVE Enrichment