CVE-2024-6749
CVE-2024-6749
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.3EPSS 0.1%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
26 Nov 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Seth Fogie, member of the AXIS Camera Station Pro Bug Bounty Program, has found that the Incident report feature may expose sensitive credentials on the AXIS Camera Station windows client. If Incident report is not being used with credentials configured this flaw does not apply.
Axis has released patched versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Affected products
Axis Communications AB · AXIS Camera StationAxis Communications AB · AXIS Camera Station ProWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →