{ "id": "CVE-2023-21405", "sourceIdentifier": "product-security@axis.com", "published": "2023-07-25T08:15:09.927", "lastModified": "2024-11-21T07:42:47.763", "vulnStatus": "Modified", "cveTags": [], "descriptions": [ { "lang": "en", "value": "Knud from Fraktal.fi has found a flaw in some Axis Network Door Controllers and Axis Network\nIntercoms when communicating over OSDP, highlighting that the OSDP message parser crashes\nthe pacsiod process, causing a temporary unavailability of the door-controlling functionalities\nmeaning that doors cannot be opened or closed. No sensitive or customer data can be extracted\nas the Axis device is not further compromised. Please refer to the Axis security advisory for more information, mitigation and affected products and software versions." } ], "metrics": { "cvssMetricV31": [ { "source": "product-security@axis.com", "type": "Secondary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "ADJACENT_NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" }, "exploitabilityScore": 2.8, "impactScore": 3.6 }, { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "ADJACENT_NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" }, "exploitabilityScore": 2.8, "impactScore": 3.6 } ] }, "weaknesses": [ { "source": "product-security@axis.com", "type": "Secondary", "description": [ { "lang": "en", "value": "CWE-1286" } ] }, { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "NVD-CWE-noinfo" } ] }, { "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary", "description": [ { "lang": "en", "value": "CWE-754" } ] } ], "configurations": [ { "operator": "AND", "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:axis:a1001_firmware:*:*:*:*:*:*:*:*", "versionEndIncluding": "1.65.4", "matchCriteriaId": "250BA4C3-1498-4C31-9199-ED26336E4467" } ] }, { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": false, "criteria": "cpe:2.3:h:axis:a1001:-:*:*:*:*:*:*:*", "matchCriteriaId": "17AB03CB-201D-4838-AA48-EE2BEABB1DDE" } ] } ] }, { "operator": "AND", "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:axis:a1210_\\(-b\\)_firmware:*:*:*:*:*:*:*:*", "versionStartIncluding": "11.0", "versionEndIncluding": "11.6.16.0", "matchCriteriaId": "1025D3EF-359A-42F8-A6F3-A1A913BC84FF" } ] }, { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": false, "criteria": "cpe:2.3:h:axis:a1210_\\(-b\\):-:*:*:*:*:*:*:*", "matchCriteriaId": "A1CDF5C3-76A2-4D39-91C7-0F6D76EA2D0C" } ] } ] }, { "operator": "AND", "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:axis:a1601_firmware:*:*:*:*:*:*:*:*", "versionEndIncluding": "1.84.4", "matchCriteriaId": "0CF7DD49-AC16-4AF1-BCFF-7E9B385C17D7" }, { "vulnerable": true, "criteria": "cpe:2.3:o:axis:a1601_firmware:*:*:*:*:*:*:*:*", "versionStartIncluding": "10.0", "versionEndIncluding": "10.12.171.0", "matchCriteriaId": "6ADF9CDC-B131-4568-9E40-51534D18B033" }, { "vulnerable": true, "criteria": "cpe:2.3:o:axis:a1601_firmware:*:*:*:*:*:*:*:*", "versionStartIncluding": "11.0", "versionEndIncluding": "11.6.16.0", "matchCriteriaId": "4AF50B3C-1DBC-4B90-8437-8FFB40878611" } ] }, { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": false, "criteria": "cpe:2.3:h:axis:a1601:-:*:*:*:*:*:*:*", "matchCriteriaId": "1D256893-7BD3-40A6-9877-2DED01770AC5" } ] } ] }, { "operator": "AND", "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:axis:a1610_\\(-b\\)_firmware:*:*:*:*:*:*:*:*", "versionEndIncluding": "10.12.171.0", "matchCriteriaId": "650F99B2-0A4E-4642-BFEE-83E137EE1940" }, { "vulnerable": true, "criteria": "cpe:2.3:o:axis:a1610_\\(-b\\)_firmware:*:*:*:*:*:*:*:*", "versionStartIncluding": "11.0", "versionEndIncluding": "11.6.16.0", "matchCriteriaId": "B19B16FF-93F4-46BF-B629-3FDE840EAE2D" } ] }, { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": false, "criteria": "cpe:2.3:h:axis:a1610_\\(-b\\):-:*:*:*:*:*:*:*", "matchCriteriaId": "02A7D1B6-D87A-47DF-8CB4-76AD56B450EA" } ] } ] }, { "operator": "AND", "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:axis:axis_os:*:*:*:*:*:*:*:*", "versionEndIncluding": "10.12.178", "matchCriteriaId": "ED306393-885B-4898-95C7-CE5F61B96ED2" }, { "vulnerable": true, "criteria": "cpe:2.3:o:axis:axis_os:*:*:*:*:*:*:*:*", "versionStartIncluding": "11.0", "versionEndIncluding": "11.5.53", "matchCriteriaId": "352DA079-F861-49FF-AA51-F98F1188DFFE" } ] }, { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": false, "criteria": "cpe:2.3:h:axis:a8207:-:*:*:*:*:*:*:*", "matchCriteriaId": "498E4857-D25F-4827-8328-023B02A64006" } ] } ] }, { "operator": "AND", "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:axis:axis_os:*:*:*:*:*:*:*:*", "versionEndIncluding": "10.12.178", "matchCriteriaId": "ED306393-885B-4898-95C7-CE5F61B96ED2" }, { "vulnerable": true, "criteria": "cpe:2.3:o:axis:axis_os:*:*:*:*:*:*:*:*", "versionStartIncluding": "11.0", "versionEndIncluding": "11.5.53", "matchCriteriaId": "352DA079-F861-49FF-AA51-F98F1188DFFE" } ] }, { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": false, "criteria": "cpe:2.3:h:axis:a8207_mkii:-:*:*:*:*:*:*:*", "matchCriteriaId": "8AEF2999-77C1-4B5D-A633-FCE9E49F8376" } ] } ] } ], "references": [ { "url": "https://www.axis.com/dam/public/7f/3a/ed/cve-2023-21405-en-US-407244.pdf", "source": "product-security@axis.com", "tags": [ "Vendor Advisory" ] }, { "url": "https://www.axis.com/dam/public/7f/3a/ed/cve-2023-21405-en-US-407244.pdf", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ] } ] }