ZDI-25-858: Axis Communications Autodesk Plugin AzureBlobRestAPI axiscontentfiles Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Axis Communications Autodesk Plugin. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-858?
The CVSS rating for ZDI-25-858 is 8.8, indicating a high severity vulnerability.
How do I fix ZDI-25-858?
To remediate ZDI-25-858, apply the latest security patches from Axis Communications for the Autodesk Plugin.
What types of attacks can exploit ZDI-25-858?
ZDI-25-858 allows remote attackers to execute arbitrary code on vulnerable installations without requiring authentication.
What versions of the Axis Communications Autodesk Plugin are affected by ZDI-25-858?
ZDI-25-858 affects all installations of the Axis Communications Autodesk Plugin that are not updated with the latest security fixes.
Is user authentication required to exploit ZDI-25-858?
No, user authentication is not required to exploit the vulnerability ZDI-25-858.