Impact
A buffer overflow exists in the Signed Video Framework that can cause the software that performs signed content validation to crash. The flaw does not affect the AXIS OS device’s signed video playback path. The resulting denial of service could interrupt automated validation workflows or maintenance tasks that rely on the affected tools.
Affected Systems
Axis Communications AB products, specifically the Axis File Player, Signed Video Framework, and Signed media verifier. No vendor‑reported version information is available, so all current releases of these tools are potentially affected.
Risk and Exploitability
The CVSS score is 5.3, indicating moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting that no widespread exploitation has been observed. Exploitation would most likely require an attacker to supply maliciously crafted signed content that the validation tool processes, which may be possible via local or remote interfaces that accept such content. Based on the description, a successfully triggered overflow would crash the application but could not be exploited for arbitrary code execution.
OpenCVE Enrichment