cbcvebase.
CVE-2023-21405
published 2023-07-25

CVE-2023-21405: Knud from Fraktal.fi has found a flaw in some Axis Network Door Controllers and Axis Network Intercoms when communicating over OSDP, highlighting that the OSDP…

medium6.5CVSS 3.1
AVAACLPRNUINSUCNINAH
Knud from Fraktal.fi has found a flaw in some Axis Network Door Controllers and Axis Network Intercoms when communicating over OSDP, highlighting that the OSDP message parser crashes the pacsiod process, causing a temporary unavailability of the door-controlling functionalities meaning that doors cannot be opened or closed. No sensitive or customer data can be extracted as the Axis device is not further compromised. Please refer to the Axis security advisory for more information, mitigation and affected products and software versions.

Affected

20 ranges
VendorProductVersion rangeFixed in
axisa1001_firmware<= 1.65.4
axisa1210_firmware11.0 – 11.6.16.0
axisa1601_firmware<= 1.84.4
axisa1601_firmware10.0 – 10.12.171.0
axisa1601_firmware11.0 – 11.6.16.0
axisa1610_firmware<= 10.12.171.0
axisa1610_firmware11.0 – 11.6.16.0
axisaxis_os<= 10.12.178
axisaxis_os11.0 – 11.5.53
axis_communications_abaxis_a1001_network_door_controller
axis_communications_abaxis_a1210-b_network_door_controller
axis_communications_abaxis_a1601_network_door_controller
axis_communications_abaxis_a1601_network_door_controller
axis_communications_abaxis_a1601_network_door_controller
axis_communications_abaxis_a1610_network_door_controller
axis_communications_abaxis_a1610_network_door_controller
axis_communications_abaxis_a8207-ve_mk_ii_network_video_door_station
axis_communications_abaxis_a8207-ve_mk_ii_network_video_door_station
axis_communications_abaxis_a8207-ve_network_video_door_station
axis_communications_abaxis_a8207-ve_network_video_door_station