CVE-2023-5553

HIGH

AXIS OS 10.8-11.7.56 and AXIS OS 2022 < 10.12.213 - Incorrect Authorization

Title source: llm
STIX 2.1

Description

During internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device tampering (commonly known as Secure Boot) in AXIS OS making it vulnerable to a sophisticated attack to bypass this protection. To Axis' knowledge, there are no known exploits of the vulnerability at this time. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.

References (1)

Core 1

Scores

CVSS v3 7.6
EPSS 0.0033
EPSS Percentile 24.8%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-863
Status published
Products (2)
axis/axis_os 10.8 - 11.7.57
axis/axis_os_2022 < 10.12.213
Published Nov 21, 2023
Tracked Since Feb 18, 2026