Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-21417

Опубликовано: 21 нояб. 2023
Источник: nvd
CVSS3: 7.1
EPSS Низкий

Описание

Sandro Poppi, member of the AXIS OS Bug Bounty Program,

has found that the VAPIX API manageoverlayimage.cgi was vulnerable to path traversal attacks that allows for file/folder deletion. This flaw can only be exploited after authenticating with an operator- or administrator- privileged service account. The impact of exploiting this vulnerability is lower with operator service accounts and limited to non-system files compared to administrator-privileges. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:o:axis:axis_os:*:*:*:*:active:*:*:*
Версия до 11.7.57 (исключая)
cpe:2.3:o:axis:axis_os_2020:*:*:*:*:lts:*:*:*
Версия до 9.80.49 (исключая)
cpe:2.3:o:axis:axis_os_2022:*:*:*:*:lts:*:*:*
Версия до 10.12.208 (исключая)

EPSS

Процентиль: 41%
0.00193
Низкий

7.1 High

CVSS3

Дефекты

CWE-35
CWE-22

Связанные уязвимости

CVSS3: 7.1
github
около 2 лет назад

Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API manageoverlayimage.cgi was vulnerable to path traversal attacks that allows for file/folder deletion. This flaw can only be exploited after authenticating with an operator- or administrator- privileged service account. The impact of exploiting this vulnerability is lower with operator service accounts and limited to non-system files compared to administrator-privileges. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.

CVSS3: 7.1
fstec
около 2 лет назад

Уязвимость реализации прикладного программного интерфейса VAPIX операционной системы AXIS OS, позволяющая нарушителю удалить произвольные файлы

EPSS

Процентиль: 41%
0.00193
Низкий

7.1 High

CVSS3

Дефекты

CWE-35
CWE-22