Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX APIs local_list.cgi, create_overlay.cgi and irissetup.cgi was vulnerable for file globbing which could lead to a resource exhaustion attack. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
双字符或匹配符号转义处理不恰当
Vulnerability Title
AXIS OS 安全漏洞
Vulnerability Description
AXIS Os是瑞典安讯士(AXIS)公司的一种边缘设备操作系统。 AXIS OS 6.50至11.8版本存在安全漏洞,该漏洞源于VAPIX APIs local_list.cgi, create_overlay.cgi和irissetup.cgi易受文件通配(file globbing)攻击而导致资源耗尽。
CVSS Information
N/A
Vulnerability Type
N/A