3.8
CWE
1286 20 77
Advisory Published
Updated

CVE-2024-8160: Input Validation

First published: Tue Nov 26 2024(Updated: )

Erik de Jong, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API ftptest.cgi did not have a sufficient input validation allowing for a possible command injection leading to being able to transfer files from/to the Axis device. This flaw can only be exploited after authenticating with an administrator-privileged service account. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.

Credit: product-security@axis.com

Affected SoftwareAffected VersionHow to fix
AXIS OS

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2024-8160?

    CVE-2024-8160 has been classified as a high severity vulnerability due to its potential for command injection.

  • How can I fix CVE-2024-8160?

    To mitigate CVE-2024-8160, ensure that all devices running AXIS OS are updated to the latest version that addresses this vulnerability.

  • What types of devices are affected by CVE-2024-8160?

    CVE-2024-8160 affects devices running AXIS OS, particularly those utilizing the VAPIX API ftptest.cgi functionality.

  • Can CVE-2024-8160 be exploited remotely?

    CVE-2024-8160 requires authentication, meaning exploitation can only occur after an attacker gains valid access to the affected Axis device.

  • What are the potential impacts of CVE-2024-8160?

    Exploitation of CVE-2024-8160 may allow an attacker to perform unauthorized file transfers to or from the Axis device.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203