Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mvpq-6rgj-x5xq

Опубликовано: 11 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.8

Описание

The ACAP Application framework could allow privilege escalation through a symlink attack. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.

The ACAP Application framework could allow privilege escalation through a symlink attack. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.

EPSS

Процентиль: 22%
0.00072
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 6.8
nvd
3 месяца назад

The ACAP Application framework could allow privilege escalation through a symlink attack. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.

EPSS

Процентиль: 22%
0.00072
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-59