2024-12-08 03:06:42 +00:00

124 lines
3.6 KiB
JSON

{
"id": "CVE-2021-31989",
"sourceIdentifier": "product-security@axis.com",
"published": "2021-08-25T19:15:11.940",
"lastModified": "2024-11-21T06:06:40.567",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A user with permission to log on to the machine hosting the AXIS Device Manager client could under certain conditions extract a memory dump from the built-in Windows Task Manager application. The memory dump may potentially contain credentials of connected Axis devices."
},
{
"lang": "es",
"value": "Un usuario con permiso para iniciar sesi\u00f3n en la m\u00e1quina que aloja el cliente AXIS Device Manager podr\u00eda en determinadas condiciones, extraer un volcado de memoria de la aplicaci\u00f3n integrada Windows Task Manager. El volcado de memoria puede contener potencialmente unas credenciales de los dispositivos Axis conectados."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"attackVector": "NETWORK",
"attackComplexity": "HIGH",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 1.6,
"impactScore": 3.6
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:S/C:P/I:N/A:N",
"baseScore": 3.5,
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "SINGLE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "NONE",
"availabilityImpact": "NONE"
},
"baseSeverity": "LOW",
"exploitabilityScore": 6.8,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "product-security@axis.com",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-316"
}
]
},
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-312"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:axis:device_manager:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.00.010",
"versionEndIncluding": "5.16.063",
"matchCriteriaId": "3E80CCEB-0BDB-4ABB-B6EA-A45D86299E02"
}
]
}
]
}
],
"references": [
{
"url": "https://www.axis.com/files/tech_notes/CVE-2021-31989.pdf",
"source": "product-security@axis.com",
"tags": [
"Vendor Advisory"
]
},
{
"url": "https://www.axis.com/files/tech_notes/CVE-2021-31989.pdf",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Vendor Advisory"
]
}
]
}