CVE-2023-21409: Insufficient file permissions leak administrator-privileged credentials in AXIS License Verifier ACAP
Due to insufficient file permissions, unprivileged users could gain access to unencrypted administrator credentials allowing the configuration of the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-21409?
The severity of CVE-2023-21409 is critical with a severity value of 9.8.
How can unprivileged users gain access to unencrypted administrator credentials in CVE-2023-21409?
Unprivileged users can gain access to unencrypted administrator credentials in CVE-2023-21409 due to insufficient file permissions.
What is the affected software in CVE-2023-21409?
The affected software in CVE-2023-21409 is AXIS License Plate Verifier version up to 2.8.3.
How can the vulnerability be fixed in CVE-2023-21409?
To fix the vulnerability in CVE-2023-21409, the file permissions need to be properly configured to prevent unprivileged users from accessing unencrypted administrator credentials.
Where can I find more information about CVE-2023-21409?
More information about CVE-2023-21409 can be found at the following reference link: [https://www.axis.com/dam/public/0b/1c/96/cve-2023-2140712-en-US-409778.pdf](https://www.axis.com/dam/public/0b/1c/96/cve-2023-2140712-en-US-409778.pdf)