CVE-2024-47260
51l3nc3, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API mediaclip.cgi did not have a sufficient input validation allowing for uploading more audio clips then designed resulting in the Axis device running out of memory. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS probability
- 0.40%
- CWE
- CWE-641
- Published
- 2025-03-04
- Last modified
- 2026-03-13
Affected products
- Axis Communications AB AXIS OS
- Axis Communications AB AXIS OS
- Axis Communications AB AXIS OS
- Axis Communications AB AXIS OS
Weakness type
Related vulnerabilities
- CVE-2026-46581 — In Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not...
- CVE-2026-50510 — GitHub Copilot Remote Code Execution Vulnerability
- CVE-2026-50023 — yt-dlp: Dangerous file type creation via insufficient filename sanitization (Bypass of CVE-2024-38519)
- CVE-2019-25623 — Luminance Studio 2.17 Denial of Service via Malformed Input
- CVE-2026-25177 — Active Directory Domain Services Elevation of Privilege Vulnerability
- CVE-2025-47173 — Microsoft Office Remote Code Execution Vulnerability
- CVE-2025-47953 — Microsoft Office Remote Code Execution Vulnerability
- CVE-2025-21402 — Microsoft Office OneNote Remote Code Execution Vulnerability