PT-2023-7484 · Axis · Axis Os

CVE-2023-21417

·

Publicado

2023-11-21

·

Atualizado

2024-11-08

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:S/C:N/I:P/A:C
Name of the Vulnerable Software and Affected Versions AXIS OS versions prior to the patched version
Description The issue is related to the VAPIX API in the AXIS OS, specifically with the manageoverlayimage.cgi endpoint. It allows for path traversal attacks, enabling an attacker to delete arbitrary files after authenticating with an operator- or administrator-privileged service account. The impact of exploiting this issue is lower with operator service accounts and is limited to non-system files compared to administrator-privileges.
Recommendations For versions prior to the patched version, update to the patched AXIS OS version as released by Axis to resolve the issue. As a temporary workaround, consider restricting access to the manageoverlayimage.cgi endpoint until a patch is applied. Additionally, limit the use of administrator-privileged service accounts to minimize the risk of exploitation.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-08528
CVE-2023-21417

Produtos afetados

Axis Os