CVE-2024-7696 – AXIS Camera Station Audit Log Tampering and Attack Vector Vulnerability

The following table lists the changes that have been made to the
CVE-2024-7696 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Jan. 07, 2025

    Action Type Old Value New Value
    Added Description Seth Fogie, member of AXIS Camera Station Pro Bug Bounty Program, has found that it is possible for an authenticated malicious client to tamper with audit log creation in AXIS Camera Station, or perform a Denial-of-Service attack on the AXIS Camera Station server using maliciously crafted audit log entries.
    Axis has released a patched version for the highlighted flaw. Please
    refer to the Axis security advisory for more information and solution.
    Added CVSS V3.1 AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
    Added CWE CWE-117
    Added Reference https://www.axis.com/dam/public/b3/53/03/cve-2024-7696-en-US-459552.pdf
Share the Post:

Related Posts