CVE-2023-21404: Medium severity axis os vulnerability
Published May 8, 2023
·Updated
AXIS OS 11.0.X - 11.3.x use a static RSA key in legacy LUA-components to protect Axis-specific source code. The static RSA key is not used in any other secure communication nor can it be used to compromise the device or any customer data.
Affected Software
1 affected component
Axis AXIS OS>=11.0.89<11.4.52
Event History
May 8, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
09:15 PM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-21404.
2
What is the severity of CVE-2023-21404?
The severity of CVE-2023-21404 is medium with a severity value of 5.3.
3
What is the affected software?
The affected software is AXIS OS version 11.0.X to 11.3.X.
4
How does the vulnerability impact the device or data?
The vulnerability does not compromise the device or any customer data.
5
How can the vulnerability be fixed?
Update the AXIS OS to a version higher than 11.4.52 as the vulnerability is fixed in that version.