2024-12-08 03:06:42 +00:00

312 lines
9.1 KiB
JSON

{
"id": "CVE-2023-21405",
"sourceIdentifier": "product-security@axis.com",
"published": "2023-07-25T08:15:09.927",
"lastModified": "2024-11-21T07:42:47.763",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Knud from Fraktal.fi has found a flaw in some Axis Network Door Controllers and Axis Network\nIntercoms when communicating over OSDP, highlighting that the OSDP message parser crashes\nthe pacsiod process, causing a temporary unavailability of the door-controlling functionalities\nmeaning that doors cannot be opened or closed. No sensitive or customer data can be extracted\nas the Axis device is not further compromised. Please refer to the Axis security advisory for more information, mitigation and affected products and software versions."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "product-security@axis.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"attackVector": "ADJACENT_NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"availabilityImpact": "HIGH"
},
"exploitabilityScore": 2.8,
"impactScore": 3.6
},
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"attackVector": "ADJACENT_NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"availabilityImpact": "HIGH"
},
"exploitabilityScore": 2.8,
"impactScore": 3.6
}
]
},
"weaknesses": [
{
"source": "product-security@axis.com",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-1286"
}
]
},
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-754"
}
]
}
],
"configurations": [
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:axis:a1001_firmware:*:*:*:*:*:*:*:*",
"versionEndIncluding": "1.65.4",
"matchCriteriaId": "250BA4C3-1498-4C31-9199-ED26336E4467"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:axis:a1001:-:*:*:*:*:*:*:*",
"matchCriteriaId": "17AB03CB-201D-4838-AA48-EE2BEABB1DDE"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:axis:a1210_\\(-b\\)_firmware:*:*:*:*:*:*:*:*",
"versionStartIncluding": "11.0",
"versionEndIncluding": "11.6.16.0",
"matchCriteriaId": "1025D3EF-359A-42F8-A6F3-A1A913BC84FF"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:axis:a1210_\\(-b\\):-:*:*:*:*:*:*:*",
"matchCriteriaId": "A1CDF5C3-76A2-4D39-91C7-0F6D76EA2D0C"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:axis:a1601_firmware:*:*:*:*:*:*:*:*",
"versionEndIncluding": "1.84.4",
"matchCriteriaId": "0CF7DD49-AC16-4AF1-BCFF-7E9B385C17D7"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:o:axis:a1601_firmware:*:*:*:*:*:*:*:*",
"versionStartIncluding": "10.0",
"versionEndIncluding": "10.12.171.0",
"matchCriteriaId": "6ADF9CDC-B131-4568-9E40-51534D18B033"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:o:axis:a1601_firmware:*:*:*:*:*:*:*:*",
"versionStartIncluding": "11.0",
"versionEndIncluding": "11.6.16.0",
"matchCriteriaId": "4AF50B3C-1DBC-4B90-8437-8FFB40878611"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:axis:a1601:-:*:*:*:*:*:*:*",
"matchCriteriaId": "1D256893-7BD3-40A6-9877-2DED01770AC5"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:axis:a1610_\\(-b\\)_firmware:*:*:*:*:*:*:*:*",
"versionEndIncluding": "10.12.171.0",
"matchCriteriaId": "650F99B2-0A4E-4642-BFEE-83E137EE1940"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:o:axis:a1610_\\(-b\\)_firmware:*:*:*:*:*:*:*:*",
"versionStartIncluding": "11.0",
"versionEndIncluding": "11.6.16.0",
"matchCriteriaId": "B19B16FF-93F4-46BF-B629-3FDE840EAE2D"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:axis:a1610_\\(-b\\):-:*:*:*:*:*:*:*",
"matchCriteriaId": "02A7D1B6-D87A-47DF-8CB4-76AD56B450EA"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:axis:axis_os:*:*:*:*:*:*:*:*",
"versionEndIncluding": "10.12.178",
"matchCriteriaId": "ED306393-885B-4898-95C7-CE5F61B96ED2"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:o:axis:axis_os:*:*:*:*:*:*:*:*",
"versionStartIncluding": "11.0",
"versionEndIncluding": "11.5.53",
"matchCriteriaId": "352DA079-F861-49FF-AA51-F98F1188DFFE"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:axis:a8207:-:*:*:*:*:*:*:*",
"matchCriteriaId": "498E4857-D25F-4827-8328-023B02A64006"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:axis:axis_os:*:*:*:*:*:*:*:*",
"versionEndIncluding": "10.12.178",
"matchCriteriaId": "ED306393-885B-4898-95C7-CE5F61B96ED2"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:o:axis:axis_os:*:*:*:*:*:*:*:*",
"versionStartIncluding": "11.0",
"versionEndIncluding": "11.5.53",
"matchCriteriaId": "352DA079-F861-49FF-AA51-F98F1188DFFE"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:axis:a8207_mkii:-:*:*:*:*:*:*:*",
"matchCriteriaId": "8AEF2999-77C1-4B5D-A633-FCE9E49F8376"
}
]
}
]
}
],
"references": [
{
"url": "https://www.axis.com/dam/public/7f/3a/ed/cve-2023-21405-en-US-407244.pdf",
"source": "product-security@axis.com",
"tags": [
"Vendor Advisory"
]
},
{
"url": "https://www.axis.com/dam/public/7f/3a/ed/cve-2023-21405-en-US-407244.pdf",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Vendor Advisory"
]
}
]
}