The communication protocol used between client and server had a flaw that could lead to an authenticated user performing a remote code execution attack.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Camera_station | Axis | * | 5.58.47195 (excluding) |
| Camera_station_pro | Axis | * | 6.9.47069 (excluding) |
| Device_manager | Axis | * | 5.32.137 (excluding) |