CVE-2023-21407: Privilege escalation in AXIS License Plate Verifier ACAP
Published Aug 3, 2023
·Updated
A broken access control was found allowing for privileged escalation of the operator account to gain administrator privileges.
Affected Software
1 affected component
Axis License Plate Verifier<=2.8.3
Event History
Aug 3, 2023
CVE Published
via MITRE·06:40 AM
Data Sourced
via MITRE·06:40 AM
DescriptionSeverity
Data Sourced
07:15 AM
Description
Frequently Asked Questions
1
What is CVE-2023-21407?
CVE-2023-21407 is a vulnerability that allows for privileged escalation of the operator account to gain administrator privileges due to a broken access control in AXIS License Plate Verifier.
2
How severe is CVE-2023-21407?
CVE-2023-21407 has a severity score of 8.8 (high).
3
How does CVE-2023-21407 affect AXIS License Plate Verifier?
CVE-2023-21407 affects AXIS License Plate Verifier version up to and including 2.8.3.
4
What is the fix for CVE-2023-21407?
To fix CVE-2023-21407, update AXIS License Plate Verifier to a version that addresses the broken access control vulnerability.
5
Where can I find more information about CVE-2023-21407?
More information about CVE-2023-21407 can be found at the following reference: [link](https://www.axis.com/dam/public/0b/1c/96/cve-2023-2140712-en-US-409778.pdf).