CVE-2024-33898: Axiros Axess
Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.
Axiros AXESS Auto Configuration Server (ACS) 4.x and 5.0.0 is affected by an Incorrect Access Control vulnerability. An authorization bypass allows remote attackers to achieve unauthenticated remote code execution.
Affected products
- Axiros Axess: from 4.0, before 5.0.0 (fixed in 5.0.0); version 5.0.0 only
Published 2024-06-24. Last modified 2026-06-17.