cbcvebase.
CVE-2023-5677
published 2024-02-05

CVE-2023-5677: Brandon Rothel from QED Secure Solutions and Sam Hanson of Dragos have found that the VAPIX API tcptest.cgi did not have a sufficient input validation allowing…

high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
Brandon Rothel from QED Secure Solutions and Sam Hanson of Dragos have found that the VAPIX API tcptest.cgi did not have a sufficient input validation allowing for a possible remote code execution. This flaw can only be exploited after authenticating with an operator- or administrator-privileged service account. The impact of exploiting this vulnerability is lower with operator-privileges compared to administrator-privileges service accounts. Please refer to the Axis security advisory for more information and solution.

Affected

13 ranges
VendorProductVersion rangeFixed in
axism3024-lve_firmware< 5.51.7.75.51.7.7
axism3025-ve_firmware< 5.51.7.75.51.7.7
axism7014_firmware< 5.51.7.75.51.7.7
axism7016_firmware< 5.51.7.75.51.7.7
axisp1214-e_firmware< 5.51.7.75.51.7.7
axisp7214_firmware< 5.51.7.75.51.7.7
axisp7216_firmware< 5.51.7.75.51.7.7
axisq7401_firmware< 5.51.7.75.51.7.7
axisq7404_firmware< 5.51.7.75.51.7.7
axisq7414_firmware< 5.51.7.75.51.7.7
axisq7424-r_mk_ii_firmware< 5.51.3.95.51.3.9
axis_communications_abaxis_os
axis_communications_abaxis_os