CVE-2024-47260 Details
Description
51l3nc3, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API mediaclip.cgi did not have a sufficient input validation allowing for uploading more audio clips then designed resulting in the Axis device running out of memory. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.
A denial-of-service vulnerability has been identified in the VAPIX API's mediaclip.cgi component, present in AXIS OS versions 9.80 prior to 12.2. This vulnerability arises from inadequate input validation, allowing users to upload more audio clips than intended, which can cause the device to exhaust its memory resources. The issue can be exploited by authenticated users with operator or administrator privileges.
Axis has released patches for this vulnerability in the following AXIS OS versions: Active Track 12.3.1, LTS 2024 11.11.135, LTS 2022 10.12.270, and LTS 2020 9.80.89. For devices not included in these tracks but still under support, patches will be provided according to the planned maintenance and release schedule.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Mar 4, 2025CISA-ADP
Assessed Mar 4, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.axis.com/dam/public/1d/d3/ef/cve-2024-47260pdf-en-US-466883.pdf | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-641 | Improper Restriction of Names for Files and Other Resources | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Axis AXIS OS | >= 9.80, <= 12.2 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 4, 2025 | New CVE Received | [email protected] |
Volerion