The VAPIX Device Configuration framework allowed a privilege escalation, enabling a lower-privileged user to gain administrator privileges.
The product receives data from an upstream component, but does not completely filter special elements before sending it to a downstream component.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Axis_os | Axis | 12.0.0 (including) | 12.3.33 (excluding) |
| Axis_os_2024 | Axis | 11.8.0 (including) | 11.11.140 (excluding) |