Vulnerabilities > Axis > Axis OS > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-11-21 CVE-2023-21416 Unspecified vulnerability in Axis OS
Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API dynamicoverlay.cgi was vulnerable to a Denial-of-Service attack allowing for an attacker to block access to the overlay configuration page in the web interface of the Axis device.
network
low complexity
axis
6.5
2023-11-21 CVE-2023-5553 Unspecified vulnerability in Axis OS and Axis OS 2022
During internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device tampering (commonly known as Secure Boot) in AXIS OS making it vulnerable to a sophisticated attack to bypass this protection.
low complexity
axis
6.8
2023-10-16 CVE-2023-21414 Unspecified vulnerability in Axis OS
NCC Group has found a flaw during the annual internal penetration test ordered by Axis Communications.
low complexity
axis
6.8
2023-07-25 CVE-2023-21405 Unspecified vulnerability in Axis products
Knud from Fraktal.fi has found a flaw in some Axis Network Door Controllers and Axis Network Intercoms when communicating over OSDP, highlighting that the OSDP message parser crashes the pacsiod process, causing a temporary unavailability of the door-controlling functionalities meaning that doors cannot be opened or closed.
low complexity
axis
6.5
2023-05-08 CVE-2023-21404 Missing Encryption of Sensitive Data vulnerability in Axis OS
AXIS OS 11.0.X - 11.3.x use a static RSA key in legacy LUA-components to protect Axis-specific source code.
network
low complexity
axis CWE-311
5.3
2021-10-05 CVE-2021-31986 Out-of-bounds Write vulnerability in Axis products
User controlled parameters related to SMTP notifications are not correctly validated.
network
high complexity
axis CWE-787
6.8