CVE-2023-21414
Published: Oct 16, 2023
Modified: Nov 8, 2024
CVSS v3.1
7.1
Description
NCC Group has found a flaw during the annual internal penetration test ordered by Axis Communications. The protection for device tampering (commonly known as Secure Boot) contains a flaw which provides an opportunity for a sophisticated attack to bypass this protection. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.
| Vendor | Product | Versions |
|---|---|---|
Axis Communications AB | AXIS OS | affected AXIS OS 10.11 - 11.5 |
Axis Communications AB | AXIS A8207-VE Mk II | affected AXIS OS 11.5 or earlier |
Axis Communications AB | AXIS Q3527-LVE | affected AXIS OS 10.11 - 11.5 |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now