Vulnerabilities found in Axis camera software
Summary
Six vulnerabilities have been discovered in Axis camera systems that could potentially allow attackers to steal credentials and gain full device privileges, according to Nozomi Networks. The vulnerabilities discovered by Nozomi Networks Labs are present in the License Plate Verifier software product offered by Axis Communications. The issues could collectively enable attackers to exfiltrate credentials to access additional systems, elevate privileges to reach forbidden functionalities and even gain arbitrary code execution with full privileges on the device. Axis Product Security Team lead Andrew Bastert said the company thanks Nozomi for their “excellent research and good collaboration” throughout the disclosure process. “Axis Communications welcomes security researchers and ethical hackers to inspect our products and applications as it is our belief that long-term sustainable cybersecurity is created through collaboration and transparency.”