Lucene search

K
nvd[email protected]NVD:CVE-2023-21414
HistoryOct 16, 2023 - 7:15 a.m.

CVE-2023-21414

2023-10-1607:15:08
web.nvd.nist.gov
3
ncc group
flaw
penetration test
axis communications
device tampering
secure boot
protection
sophisticated attack
bypass
patched
axis os
security advisory

CVSS3

6.8

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

6.9

Confidence

High

EPSS

0.002

Percentile

51.8%

NCC Group has found a flaw during the annual internal penetration test ordered by Axis Communications. The protection for device tampering (commonly known as Secure Boot) contains a flaw which provides an opportunity for a sophisticated attack to bypass this protection. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.

Affected configurations

Nvd
Node
axisaxis_osRange10.11.5510.12.206
OR
axisaxis_osRange11.0.8911.6.94active
AND
axism3215Match-
OR
axism3216Match-
OR
axism4317-plveMatch-
OR
axism4318-plveMatch-
OR
axism4327-pMatch-
OR
axism4328-pMatch-
OR
axisp1467-leMatch-
OR
axisp1468-leMatch-
OR
axisp1468-xleMatch-
OR
axisp3265-lvMatch-
OR
axisp3265-lveMatch-
OR
axisp3265-vMatch-
OR
axisp3267-lvMatch-
OR
axisp3267-lveMatch-
OR
axisp3268-lvMatch-
OR
axisp3268-lveMatch-
OR
axisp3827-pveMatch-
OR
axisp4705-plveMatch-
OR
axisp4707-plveMatch-
OR
axisq1656Match-
OR
axisq1656-bMatch-
OR
axisq1656-beMatch-
OR
axisq1656-bleMatch-
OR
axisq1656-dleMatch-
OR
axisq1656-leMatch-
OR
axisq1961-teMatch-
OR
axisq2101-teMatch-
OR
axisq3536-lveMatch-
OR
axisq3538-lveMatch-
OR
axisq3626-veMatch-
OR
axisq3628-veMatch-
OR
axisxfq1656Match-
Node
axisaxis_osRange<11.6.94active
AND
axisa8207-ve_mk_iiMatch-
Node
axisaxis_osRange10.11.5510.12.206
OR
axisaxis_osRange11.0.8911.6.94active
AND
axisq3527-lveMatch-
VendorProductVersionCPE
axisaxis_os*cpe:2.3:o:axis:axis_os:*:*:*:*:*:*:*:*
axisaxis_os*cpe:2.3:o:axis:axis_os:*:*:*:*:active:*:*:*
axism3215-cpe:2.3:h:axis:m3215:-:*:*:*:*:*:*:*
axism3216-cpe:2.3:h:axis:m3216:-:*:*:*:*:*:*:*
axism4317-plve-cpe:2.3:h:axis:m4317-plve:-:*:*:*:*:*:*:*
axism4318-plve-cpe:2.3:h:axis:m4318-plve:-:*:*:*:*:*:*:*
axism4327-p-cpe:2.3:h:axis:m4327-p:-:*:*:*:*:*:*:*
axism4328-p-cpe:2.3:h:axis:m4328-p:-:*:*:*:*:*:*:*
axisp1467-le-cpe:2.3:h:axis:p1467-le:-:*:*:*:*:*:*:*
axisp1468-le-cpe:2.3:h:axis:p1468-le:-:*:*:*:*:*:*:*
Rows per page:
1-10 of 361

CVSS3

6.8

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

6.9

Confidence

High

EPSS

0.002

Percentile

51.8%

Related for NVD:CVE-2023-21414