First published: Wed Aug 25 2021(Updated: )
A user with permission to log on to the machine hosting the AXIS Device Manager client could under certain conditions extract a memory dump from the built-in Windows Task Manager application. The memory dump may potentially contain credentials of connected Axis devices.
Credit: product-security@axis.com product-security@axis.com
Affected Software | Affected Version | How to fix |
---|---|---|
AXIS Device Manager | >=5.00.010<=5.16.063 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-31989 is a vulnerability that allows a user with permission to log on to the machine hosting the AXIS Device Manager client to extract a memory dump from the built-in Windows Task Manager application, potentially exposing credentials of connected Axis devices.
CVE-2021-31989 affects AXIS Device Manager versions between 5.00.010 and 5.16.063.
CVE-2021-31989 has a severity rating of 5.3, which is considered medium.
To mitigate CVE-2021-31989, it is recommended to update AXIS Device Manager to a version beyond 5.16.063.
You can find more information about CVE-2021-31989 in the tech notes provided by Axis Communications: [link here]