Vulnerabilities found in Axis camera software


By Dylan Bushell-Embling
Friday, 18 August, 2023

Vulnerabilities found in Axis camera software

Six vulnerabilities have been discovered in Axis camera systems that could potentially allow attackers to steal credentials and gain full device privileges, according to Nozomi Networks.

The vulnerabilities discovered by Nozomi Networks Labs are present in the License Plate Verifier software product offered by Axis Communications.

The issues could collectively enable attackers to exfiltrate credentials to access additional systems, elevate privileges to reach forbidden functionalities and even gain arbitrary code execution with full privileges on the device.

After discovering the vulnerabilities, Nozomi Networks informed Axis, which released additional details of the vulnerabilities as well as instructions to update the affected applications to a newer version.

The updated versions of the software can be manually installed by downloading it from the Axis webpage, or automatically installed by upgrading the device firmware to the latest version.

Axis Product Security Team lead Andrew Bastert said the company thanks Nozomi for their “excellent research and good collaboration” throughout the disclosure process.

“It is the second time after some work in 2021 that we had the pleasure now to work together with Nozomi Networks and benefited from their expertise,” he said.

“Axis Communications welcomes security researchers and ethical hackers to inspect our products and applications as it is our belief that long-term sustainable cybersecurity is created through collaboration and transparency.”

Image credit: iStock.com/tashka2000

Related News

Phishing attacks on Australian workers growing more successful

The rate of Australian workers clicking on phishing links has surged 140% since last year,...

Ingram Micro adds AlgoSec to supplier line‍-‍up

Ingram Micro has reached an agreement to distribute application‍-‍centric security...

CyberCX to be bought out by Accenture

Accenture has arranged to make its largest cybersecurity acquisition to date through the purchase...


  • All content Copyright © 2025 Westwick-Farrow Pty Ltd