Description
The Signed Video Framework contained a  buffer overflow issue

which could lead the application using this framework to crash. The issue exclusively affects the tools used for the validation of signed content. The AXIS OS device's signed video functionality remains unaffected.
Published: 2026-08-11
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A buffer overflow exists in the Signed Video Framework that can cause the software that performs signed content validation to crash. The flaw does not affect the AXIS OS device’s signed video playback path. The resulting denial of service could interrupt automated validation workflows or maintenance tasks that rely on the affected tools.

Affected Systems

Axis Communications AB products, specifically the Axis File Player, Signed Video Framework, and Signed media verifier. No vendor‑reported version information is available, so all current releases of these tools are potentially affected.

Risk and Exploitability

The CVSS score is 5.3, indicating moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting that no widespread exploitation has been observed. Exploitation would most likely require an attacker to supply maliciously crafted signed content that the validation tool processes, which may be possible via local or remote interfaces that accept such content. Based on the description, a successfully triggered overflow would crash the application but could not be exploited for arbitrary code execution.

Generated by OpenCVE AI on August 11, 2026 at 07:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Axis Communications’ website or support portal for a firmware or software update that specifically addresses the Signed Video Framework buffer overflow and apply it as soon as it becomes available.
  • If an update is not yet available, restrict or disable the usage of the affected validation tools on critical systems until a patch is released, or otherwise isolate the environment to prevent exposure to untrusted signed content.
  • Monitor system logs and application stability metrics for signs of crashes related to signed content validation, and review incidents promptly to determine if the vulnerability has been leveraged or triggered.

Generated by OpenCVE AI on August 11, 2026 at 07:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Title Signed Video Framework Buffer Overflow Causes Crash
Weaknesses CWE-119

Tue, 11 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description The Signed Video Framework contained a  buffer overflow issue which could lead the application using this framework to crash. The issue exclusively affects the tools used for the validation of signed content. The AXIS OS device's signed video functionality remains unaffected.
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Axis

Published:

Updated: 2026-08-11T05:43:06.499Z

Reserved: 2026-05-08T09:38:31.980Z

Link: CVE-2026-8158

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T07:30:03Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer