{"id":"8678b92a-d1e6-4dab-8969-adc57ee5b4d6","engagementId":"4024ed89-0e0f-4030-a492-cd7b81006f0d","data":{"brief":{"id":"757c5da1-2392-417b-a466-910981cc1dc5","name":"AXIS OS","tagline":"AXIS OS is the Linux-based operating system that powers more than 250+ Axis network products such as cameras, intercoms, access control, body-worn and speakers.","description":"\u003cp\u003eAxis Communications acknowledges the importance and hard work performed by security researchers. Thank you for working with us to help increase the security in our products and joining into our program!\u003c/p\u003e\n\n\u003ch2\u003eReport Assessment and Bounty Calculations:\u003c/h2\u003e\n\n\u003cp\u003eThis program will use the \u003ca href=\"https://www.first.org/cvss/calculator/3.1\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eCVSS v3.1 rating system\u003c/a\u003e (Common Vulnerability Scoring System). Axis may assess the vulnerability accordingly to its relevance in the context of how Axis recommends deploying its products, software, and services. In any instance where an issue is downgraded or upgraded, a full, detailed explanation will be provided. Axis will validate all submissions against the latest AXIS OS 13 device software available on \u003ca href=\"https://www.axis.com/support/device-software\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eaxis.com\u003c/a\u003e. Vulnerabilities that affect only earlier software versions are out of scope and are not eligible for a bounty.\u003c/p\u003e\n\n\u003cp\u003eP1 = CVSSv3.1 critical (9.0 – 10.0)\u003cbr\u003e\nP2 = CVSSv3.1 high (7.0 – 8.9)\u003cbr\u003e\nP3 = CVSSv3.1 medium (4.0 – 6.9)\u003cbr\u003e\nP4 = CVSSv3.1 low (0.1 – 3.9)\u003c/p\u003e\n\n\u003ch2\u003eReward payout:\u003c/h2\u003e\n\n\u003cp\u003eRewards are paid out directly once the submission is accepted as valid submission. Researchers will also receive a one-time-only swag reward in form of a \u003ca href=\"https://www.axis.com/products/axis-m1075-l\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eAXIS M1075-L\u003c/a\u003e free of charge (MSRP $350) for submissions that result in a CVE-ID. An additional bonus of up to $10.000 may be rewarded for exceptional submissions to Axis discretion. The maximum bonus will always be rewarded in accepted P1/Critical submissions.\u003c/p\u003e\n\n\u003ch2\u003eBypass reward\u003c/h2\u003e\n\n\u003cp\u003eWe welcome submissions that can bypass previously disclosed AXIS OS CVEs. If your submission is deemed valid, you will be eligible for a one-time reward of $500 per CVE. If you share new insights or techniques that increase the impact of the CVE, we'll reassess the vulnerability. In these cases, the payout will match the updated severity level, which could exceed the $500 reward.\u003c/p\u003e\n\n\u003ch2\u003eDisclosure Policy:\u003c/h2\u003e\n\n\u003cp\u003eAxis as authorized Common Vulnerability and Exposures (CVE) Numbering Authority (CNA) discloses all vulnerabilities found in the Bug Bounty Program accordingly as outlined in the \u003ca href=\"https://help.axis.com/axis-vulnerability-management-policy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eAxis Vulnerability Management Policy\u003c/a\u003e.\u003c/p\u003e\n\n\u003ch2\u003eEligibility and Fairness:\u003c/h2\u003e\n\n\u003cp\u003eTo maintain the integrity and fairness of our bug bounty program, individuals who are currently employed by Axis or who were previously employed by Axis, are not eligible to receive rewards for vulnerabilities identified through the use of internal knowledge gained during their employment.\u003cbr\u003e\nIf you are aware of a vulnerability as a result of current or past employment, we still encourage you to disclose it responsibly. While such reports may not qualify for a monetary reward, they will be reviewed and addressed with the same level of priority as all other submissions. We appreciate your cooperation in helping us ensure a transparent and equitable program for the wider security research community.\u003c/p\u003e\n\n\u003cp\u003eBy participating in this program, you acknowledge and agree that Axis may enforce Bugcrowd’s Standard Disclosure Terms if you breach any provision therein. \u003ca href=\"https://www.axis.com/dam/public/5b/cd/c0/axis-os-eula-en-US-379165.pdf\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eAxis EULA applies when accessing Axis devices through the Bug Bounty Program\u003c/a\u003e.\u003c/p\u003e","industryTagId":"46b8dcc8-bbd9-4a60-80ab-ab088c2bc3e4","targetsOverview":"\u003ch2\u003eIn-Scope Products\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eAll targets accessible in the Target \u0026amp; Access Information. All Axis-branded products, software and services that are not listed in the In-Scope Products section are automatically out of scope.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eOut-of-Scope Vulnerabilities\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eIt is by design that selected VAPIX (e.g. BasicDeviceInfo.cgi) and ONVIF (e.g. WSDLs) API endpoints provide basic device information such as software version, model number and other information that do not require authentication to access and are available anonymously.\u003cbr\u003e\n\u003c/li\u003e\n\u003cli\u003eAccess to the device is granted through the SSH console to allow researchers to test efficiently. Vulnerabilities requiring local system access, including system-level issues such as D-Bus authorization bypasses, are out of scope unless they enable vertical privilege escalations. For example, escalations from VAPIX users to the Linux root user and from regular SSH users to the root user. \u003c/li\u003e\n\u003cli\u003eVulnerabilities caused by user configurations that could be prevented by following the \u003ca href=\"https://help.axis.com/axis-os-hardening-guide\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eAxis OS Hardening Guide\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eUser uploaded created content or applications, for instance ACAPs that can be uploaded and run on Axis devices.\u003c/li\u003e\n\u003cli\u003eSocial-engineered attacks such as Cross-Site Request Forgery (CSRF) or Cross-Site scripting (XSS) vulnerabilities and/or that trick the user into accessing a malicious website or clicking on a disguised link while accessing the web interface of Axis devices. \u003c/li\u003e\n\u003cli\u003eVulnerabilities in Axis-branded pre-installed or uploaded applications (ACAPs), for instance AXIS Object Analytics or AXIS Video Motion Detection.\u003c/li\u003e\n\u003cli\u003eVulnerabilities listed by 3rd party network security scanners such as 3rd party and open-source component vulnerabilities or missing HTTP(S) security headers such as X-Frame-Options.\u003c/li\u003e\n\u003cli\u003eAny DoS type attack such as resource exhaustion of a device through normal API usage with modified parameter inputs, high frequency API calls or using slowloris attacks.\u003c/li\u003e\n\u003cli\u003eErrors in API documentation.\u003c/li\u003e\n\u003cli\u003eGUI flaws/errors that can be corrected through the VAPIX/Onvif API.\u003c/li\u003e\n\u003cli\u003eAttacks that depends on Man-in-the-Middle (MitM) conditions.\u003c/li\u003e\n\u003cli\u003eFunctionality restricted by \u003ca href=\"https://developer.axis.com/vapix/network-video/feature-flag-service/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003efeature flags\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eThe targets in this program contain a custom script that makes sure device passwords are reset in a specific interval to ensure access. This script and it's functionality is out-of-scope for this program. \u003c/li\u003e\n\u003c/ul\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"74f4846a-bfa5-4537-a767-199a64cd12ec","name":"AXIS OS ","targets":[{"id":"420af7cf-9662-4bfd-825e-be87cef24c27","uri":"","name":"AXIS OS","category":"iot","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"7717faf9-e845-4fed-8e32-bbe07a6c512a","sortOrder":0},"sortOrder":0,"tags":[{"id":"4cb84232-a78c-4fc6-b51e-cbe67d4ee5f1","name":"IoT","targetId":"420af7cf-9662-4bfd-825e-be87cef24c27"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"76cf3afa-b3ef-4dd4-8a0b-d270eb9e0eb4","p1MaxCents":4000000,"p1MinCents":4000000,"p2MaxCents":1000000,"p2MinCents":1000000,"p3MaxCents":200000,"p3MinCents":200000,"p4MaxCents":50000,"p4MinCents":50000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":5000000},"descriptionHtml":"\u003ch2\u003eTarget \u0026amp; Access Information:\u003c/h2\u003e\n\n\u003cp\u003eYou are testing AXIS OS. AXIS OS is our Linux based operating system for edge devices. It is used in more than 400 products. While Axis does currently not provide direct access to embedded devices running the target (AXIS OS) we accept any findings if within scope.\u003c/p\u003e\n\n\u003ch2\u003eRecommendations and how-to\u003c/h2\u003e\n\n\u003col\u003e\n\u003cli\u003e API endpoints for testing are documented here \u003ca href=\"https://www.axis.com/vapix-library/subjects/T10175981/section/t10035974/display\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eVAPIX library\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e Many parameters are listed also under this API endpoint https://ip-address/axis-cgi/param.cgi?action=list. How to manage these parameters see this section in \u003ca href=\"https://www.axis.com/vapix-library/subjects/T10175981/section/t10036014/display\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eVAPIX library\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e Browsing the built-in web interface of the device and using the F12-browser console can also be used to lookup API endpoints\u003c/li\u003e\n\u003cli\u003e For privilege escalations, accounts with different privileges (administrator, operator, viewer) can be created using the built-in web interface\u003c/li\u003e\n\u003cli\u003e The administrator, operator or viewer accounts can be used for web-interface (HTTPS) and VAPIX/ONVIF API interfaces access only.\u003c/li\u003e\n\u003cli\u003e Do not change the root password or factory default the device. \u003c/li\u003e\n\u003c/ol\u003e","rewardRangeData":{"1":{"min":40000,"max":40000},"2":{"min":10000,"max":10000},"3":{"min":2000,"max":2000},"4":{"min":500,"max":500},"5":{"min":null,"max":null},"programMax":50000},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"4024ed89-0e0f-4030-a492-cd7b81006f0d","code":"axis-os-public","state":"in_progress","endsAt":null,"bountyId":"f3ea934f-74ba-4816-9081-b2decbd216b6","startsAt":"2024-09-24T00:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Technology","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/cc3b/ae90/f294612c/248c666f7a6e8531fb7765a9325353b2_Untitled.png","logoBackgroundColor":"#FFCC33","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2024-09-24T00:00:00.033Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/axis-os-public","changelogs":"/engagements/axis-os-public/changelog","submissions":null,"announcements":"/engagements/axis-os-public/announcements","hallOfFame":"/engagements/axis-os-public/hall_of_fames","crowdstream":"/engagements/axis-os-public/crowdstream"},"announcementsCount":7,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/axis-os-public/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=axis-os-public\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/axis-os-public/engagement_subscribers","engagementChangelogsUrl":"/engagements/axis-os-public/changelog","publishedAt":"2026-09-25T11:15:40.368Z","engagementChangelogUrl":"/engagements/axis-os-public/changelog/8678b92a-d1e6-4dab-8969-adc57ee5b4d6","createUserFeedbacksUrl":"/engagements/axis-os-public/feedbacks","engagementCrowdstreamUrl":"/engagements/axis-os-public/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}