CVE-2024-0055
Published: 19 March 2024
Summary
CVE-2024-0055 is a medium-severity Improper Neutralization of Wildcards or Matching Symbols (CWE-155) vulnerability in Axis OS (inferred from references). Its CVSS base score is 6.5 (Medium).
Operationally, ranked at the 41.2th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2024-15858
Vulnerability details
Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX APIs mediaclip.cgi and playclip.cgi was vulnerable for file globbing which could lead to a resource exhaustion attack. Axis has released patched AXIS OS versions for…
more
the highlighted flaw. Please refer to the Axis security advisory for more information and solution.
- CWE(s)
Related Threats
No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.
Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.