CVE-2023-21417
CVSS 3.1 Score 7.1 of 10 (high)
Details
Summary
CVE-2023-21417 is a newly discovered vulnerability in Axis Communications' VAPIX API manageoverlayimage.cgi. Sandro Poppi, a member of the AXIS OS Bug Bounty Program, discovered that this API was susceptible to path traversal attacks. These attacks allow for file and folder deletion, but they can only be exploited after authentication with an operator- or administrator-privileged service account. The impact of this vulnerability is less severe when exploited using operator accounts, as it is limited to non-system files. Axis Communications has released patched versions of AXIS OS to address this issue. Please refer to the Axis security advisory for more information and solutions.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Axis OS