CVE-2023-21417 is a path traversal vulnerability in the VAPIX API manageoverlayimage.cgi of AXIS OS, affecting various versions of Axis OS. This flaw allows authenticated attackers to delete files and folders, with the impact varying based on the privilege level of the exploited service account. Rated 7.1 HIGH on CVSS, it requires prior authentication (operator or administrator) but has low attack complexity and can lead to high availability impact. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 11.7.57CPE matchmatch criteria | cpe:2.3:o:axis:axis_os:*:*:*:*:active:*:*:* | ||
< 9.80.49CPE matchmatch criteria | cpe:2.3:o:axis:axis_os_2020:*:*:*:*:lts:*:*:* | ||
< 10.12.208CPE matchmatch criteria | cpe:2.3:o:axis:axis_os_2022:*:*:*:*:lts:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.