CVE-2021-31986
published 2021-10-05CVE-2021-31986: User controlled parameters related to SMTP notifications are not correctly validated. This can lead to a buffer overflow resulting in crashes and data leakage.
PriorityP429medium6.8CVSS 3.1
AVNACHPRNUIRSUCHINAH
EPSS
0.78%
52.1th percentile
User controlled parameters related to SMTP notifications are not correctly validated. This can lead to a buffer overflow resulting in crashes and data leakage.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| axis | axis_os | < 10.7 | 10.7 |
| axis | axis_os_2016 | < 6.50.5.5 | 6.50.5.5 |
| axis | axis_os_2018 | < 8.40.4.3 | 8.40.4.3 |
| axis | axis_os_2020 | < 9.80.3.5 | 9.80.3.5 |
| axis_communications_ab | axis_os | — | — |
CVSS provenance
nvdv3.16.8MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:H/Au:N/C:P/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
ET INFO Suspicious POST to Axis OS (smtptest.cgi)
suricata·2021-10-06
CVE-2021-31986 ET INFO Suspicious POST to Axis OS (smtptest.cgi)
ET INFO Suspicious POST to Axis OS (smtptest.cgi)
Rule: alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET INFO Suspicious POST to Axis OS (smtptest.cgi)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/axis-cgi/smtptest.cgi"; fast_pattern; reference:url,nozominetworks.com/blog/new-axis-os-security-research-aided-by-transparent-design/; reference:cve,2021-31986; classtype:bad-unknown; sid:2034130; rev:2; metadata:attack_target Server, created_at 2021_10_06, cve CVE_2021_31986, deployment Perimeter, deployment Internal, performance_impact Low, confidence High, signature_severity Informational, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2023_04_24;)
No public exploits indexed.
No writeups or analysis indexed.
2021-10-05
Published