CVE-2024-47257 Vulnerability Details

  /     /     /  

CVE-2024-47257 Metadata Quick Info

CVE Published: 26/11/2024 | CVE Updated: 29/11/2024 | CVE Year: 2024
Source: Axis | Vendor: Axis Communications AB | Product: AXIS Q6128-E PTZ Network Camera
Status : PUBLISHED

CVE-2024-47257 Description

Florent Thiéry has found that selected Axis devices were vulnerable to handling certain ethernet frames which could lead to the Axis device becoming unavailable in the network. Axis has released patched AXIS OS versions for the highlighted flaw for products that are still under AXIS OS software support. Please refer to the Axis security advisory for more information and solution.

Metrics

CVSS Version: 3.1 | Base Score: 7.5 HIGH
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

l➤ Exploitability Metrics:
    Attack Vector (AV)* NETWORK
    Attack Complexity (AC)* LOW
    Privileges Required (PR)* NONE
    User Interaction (UI)* NONE
    Scope (S)* UNCHANGED

l➤ Impact Metrics:
    Confidentiality Impact (C)* NONE
    Integrity Impact (I)* NONE
    Availability Impact (A)* HIGH

Weakness Enumeration (CWE)

CWE-ID: CWE-1284
CWE Name: CWE-1284: Improper Validation of Specified Quantity in Input
Source: Axis Communications AB

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).