PT-2023-7487 · Axis Communications · Axis Os

CVE-2023-21415

·

Publicado

2023-10-16

·

Atualizado

2024-11-08

CVSS v3.1

8.1

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions AXIS OS versions prior to the patched version
Description The issue is related to the VAPIX API in the AXIS OS, specifically with the overlay del.cgi endpoint, which is vulnerable to path traversal attacks. This allows an attacker, after authenticating with an operator- or administrator-privileged service account, to delete arbitrary files. The exploitation of this issue can be done remotely.
Recommendations For versions prior to the patched version, update to the latest AXIS OS version that includes the fix for this issue. As a temporary workaround, consider restricting access to the overlay del.cgi endpoint until a patch is available. Avoid using the overlay del.cgi endpoint with operator- or administrator-privileged service accounts until the issue is resolved.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-08531
CVE-2023-21415

Produtos afetados

Axis Os