CVE-2021-31986: Buffer Overflow
User controlled parameters related to SMTP notifications are not correctly validated. This can lead to a buffer overflow resulting in crashes and data leakage.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-31986?
CVE-2021-31986 is a vulnerability in Axis Axis Os, versions up to 10.7, Axis Axis Os 2016, versions up to 6.50.5.5, Axis Axis Os 2018, versions up to 8.40.4.3, and Axis Axis Os 2020, versions up to 9.80.3.5, where user controlled parameters related to SMTP notifications are not correctly validated, leading to a buffer overflow resulting in crashes and data leakage.
How severe is CVE-2021-31986?
CVE-2021-31986 has a severity rating of 6.8, which is considered medium.
Which software versions are affected by CVE-2021-31986?
CVE-2021-31986 affects Axis Axis Os, versions up to 10.7, Axis Axis Os 2016, versions up to 6.50.5.5, Axis Axis Os 2018, versions up to 8.40.4.3, and Axis Axis Os 2020, versions up to 9.80.3.5.
What is the Common Weakness Enumeration (CWE) ID for CVE-2021-31986?
CVE-2021-31986 has two Common Weakness Enumeration (CWE) IDs: CWE-119 and CWE-787.
How can CVE-2021-31986 be exploited?
CVE-2021-31986 can be exploited by providing user controlled parameters related to SMTP notifications that are not correctly validated, which can lead to a buffer overflow, resulting in crashes and data leakage.