PT-2021-19617 · Axis Communications+1 · Axis Os+3

Published

2021-10-05

·

Updated

2024-11-08

·

CVE-2021-31988

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: No specific software or versions are mentioned in the provided descriptions.
Description: The issue is related to a user-controlled parameter in the SMTP test functionality that is not correctly validated. This allows an attacker to add Carriage Return and Line Feed (CRLF) control characters and include arbitrary SMTP headers in the generated test email.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2021-31988

Affected Products

Axis Os
Axis Os 2016
Axis Os 2018
Axis Os 2020