CVE-2023-21413

CRITICAL

AXIS OS 10.5.0-10.12.198 and 11.0.89-11.6.93 - Remote Code Execution via ACAP Application Installation

Title source: llm
STIX 2.1

Description

GoSecure on behalf of Genetec Inc. has found a flaw that allows for a remote code execution during the installation of ACAP applications on the Axis device. The application handling service in AXIS OS was vulnerable to command injection allowing an attacker to run arbitrary code. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.

References (1)

Core 1

Scores

CVSS v3 9.1
EPSS 0.0125
EPSS Percentile 65.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-77 CWE-78
Status published
Products (2)
axis/axis_os 10.5.0 - 10.12.199
axis/axis_os 11.0.89 - 11.6.94
Published Oct 16, 2023
Tracked Since Feb 18, 2026