First published: Thu Aug 03 2023(Updated: )
A broken access control was found allowing for privileged escalation of the operator account to gain administrator privileges.
Credit: product-security@axis.com product-security@axis.com
Affected Software | Affected Version | How to fix |
---|---|---|
AXIS License Plate Verifier | <=2.8.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-21407 is a vulnerability that allows for privileged escalation of the operator account to gain administrator privileges due to a broken access control in AXIS License Plate Verifier.
CVE-2023-21407 has a severity score of 8.8 (high).
CVE-2023-21407 affects AXIS License Plate Verifier version up to and including 2.8.3.
To fix CVE-2023-21407, update AXIS License Plate Verifier to a version that addresses the broken access control vulnerability.
More information about CVE-2023-21407 can be found at the following reference: [link](https://www.axis.com/dam/public/0b/1c/96/cve-2023-2140712-en-US-409778.pdf).