PT-2023-7484 · Axis · Axis Os

Published

2023-11-21

·

Updated

2024-11-08

·

CVE-2023-21417

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:S/C:N/I:P/A:C
Name of the Vulnerable Software and Affected Versions AXIS OS versions prior to the patched version
Description The issue is related to the VAPIX API in the AXIS OS, specifically with the manageoverlayimage.cgi endpoint. It allows for path traversal attacks, enabling an attacker to delete arbitrary files after authenticating with an operator- or administrator-privileged service account. The impact of exploiting this issue is lower with operator service accounts and is limited to non-system files compared to administrator-privileges.
Recommendations For versions prior to the patched version, update to the patched AXIS OS version as released by Axis to resolve the issue. As a temporary workaround, consider restricting access to the manageoverlayimage.cgi endpoint until a patch is applied. Additionally, limit the use of administrator-privileged service accounts to minimize the risk of exploitation.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2023-08528
CVE-2023-21417

Affected Products

Axis Os