« Back to list

CVE-2024-6749

Status: DeferredMedium (6.3)—

Seth Fogie, member of the AXIS Camera Station Pro Bug Bounty Program, has found that the Incident report feature may expose sensitive credentials on the AXIS Camera Station windows client. If Incident report is not being used with credentials configured this flaw does not apply.

Axis has released patched versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2024-6749",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-6749",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-11-26T14:04:05.910545Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "product-security@axis.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.3,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.7,
        "exploitabilityScore": 2
      }
    ]
  },
  "affected": [
    {
      "source": "product-security@axis.com",
      "affectedData": [
        {
          "vendor": "Axis Communications AB",
          "product": "AXIS Camera Station Pro",
          "versions": [
            {
              "status": "affected",
              "version": "6.0 - 6.3"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Axis Communications AB",
          "product": "AXIS Camera Station",
          "versions": [
            {
              "status": "affected",
              "version": "5.25 - 5.57.27610"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-11-26T07:15:05.857",
  "references": [
    {
      "url": "https://www.axis.com/dam/public/e6/e8/1e/cve-2024-6749-en-US-455106.pdf",
      "source": "product-security@axis.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "product-security@axis.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-522"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Seth Fogie, member of the AXIS Camera Station Pro Bug Bounty Program, has found that the Incident report feature may expose sensitive credentials on the AXIS Camera Station windows client. If Incident report is not being used with credentials configured this flaw does not apply. \n\n Axis has released patched versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution."
    },
    {
      "lang": "es",
      "value": "Seth Fogie, miembro del programa Bug Bounty de AXIS Camera Station Pro, ha descubierto que la función de informe de incidentes puede exponer credenciales confidenciales en el cliente de Windows de AXIS Camera Station. Si no se utiliza el informe de incidentes con las credenciales configuradas, esta falla no se aplica. Axis ha publicado versiones parcheadas para la falla resaltada. Consulte el aviso de seguridad de Axis para obtener más información y soluciones."
    }
  ],
  "lastModified": "2026-06-17T08:18:38.243",
  "sourceIdentifier": "product-security@axis.com"
}