CVE-2024-47262 Details
Description
Dzmitry Lukyanenka, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API param.cgi was vulnerable to a race condition attack allowing for an attacker to block access to the web interface of the Axis device. Other API endpoints or services not making use of param.cgi are not affected. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.
A race condition vulnerability has been identified in the VAPIX API param.cgi on Axis devices running AXIS OS versions 6.50 through 12.2. This vulnerability allows an attacker to disrupt access to the device's web interface. Other API endpoints or services that do not utilize param.cgi are not affected. Axis has released patched versions for this flaw.
Axis has released patches for this vulnerability in the following AXIS OS versions: Active Track 12.3.4, LTS 2024 11.11.127, LTS 2022 10.12.270, LTS 2020 9.80.90, (Former LTS) 8.40.66, and (Former LTS) 6.50.5.19. For devices not included in these tracks but still under support, patches will be provided according to the planned maintenance and release schedule.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Mar 4, 2025CISA-ADP
Assessed Mar 4, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.axis.com/dam/public/a3/18/6e/cve-2024-47262pdf-en-US-466884.pdf | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1287 | Improper Validation of Specified Type of Input | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Axis AXIS OS | >= 6.50, <= 12.2 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 4, 2025 | New CVE Received | [email protected] |
Volerion