CVE-2023-21415
MEDIUMAXIS OS - Authenticated Path Traversal and Arbitrary File Deletion via VAPIX API overlay_del.cgi
Title source: llmDescription
Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API overlay_del.cgi is vulnerable to path traversal attacks that allows for file deletion. This flaw can only be exploited after authenticating with an operator- or administrator-privileged service account. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.
References (1)
Core 1
Core References
Scores
CVSS v3
6.5
EPSS
0.0059
EPSS Percentile
43.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-22
CWE-35
Status
published
Products (6)
axis/axis_os
11.0.81 - 11.6.94
axis/axis_os
6.50.5.3 - 6.50.5.14
axis/axis_os_2016
6.50.2 - 6.50.5.2
axis/axis_os_2018
< 8.40.35
axis/axis_os_2020
< 9.80.47
axis/axis_os_2022
< 10.12.206
Published
Oct 16, 2023
Tracked Since
Feb 18, 2026