PT-2021-19618 · Axis · Axis Device Manager

Published

2021-08-25

·

Updated

2024-11-08

·

CVE-2021-31989

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: AXIS Device Manager (affected versions not specified)
Description: A user with permission to log on to the machine hosting the AXIS Device Manager client could under certain conditions extract a memory dump from the built-in Windows Task Manager application. The memory dump may potentially contain credentials of connected Axis devices.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2021-31989

Affected Products

Axis Device Manager