CVE-2021-31987

Severity
7.5HIGH
EPSS
0.1%
top 71.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 5
Latest updateMay 24

Description

A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to bypass blocked network recipients.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.6 | Impact: 5.9

Affected Packages5 packages

NVDaxis/axis_os< 10.8
NVDaxis/axis_os_2016< 6.50.5.5
NVDaxis/axis_os_2018< 8.40.4.3
NVDaxis/axis_os_2020< 9.80.3.5
CVEListV5axis_communications_ab/axis_osAXIS OS 5.51 or later

🔴Vulnerability Details

2
GHSA
GHSA-xpwh-c6wc-qg9f: A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to bypass blocked network recipients2022-05-24
CVEList
CVE-2021-31987: A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to bypass blocked network recipients2021-10-05