First published: Mon Oct 16 2023(Updated: )
NCC Group has found a flaw during the annual internal penetration test ordered by Axis Communications. The protection for device tampering (commonly known as Secure Boot) contains a flaw which provides an opportunity for a sophisticated attack to bypass this protection. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.
Credit: product-security@axis.com product-security@axis.com
Affected Software | Affected Version | How to fix |
---|---|---|
AXIS AXIS OS | >=10.11.55<10.12.206 | |
AXIS AXIS OS | >=11.0.89<11.6.94 | |
Axis M3215 | ||
Axis M3216 | ||
Axis M4317-PLVE | ||
Axis M4318-PLVE | ||
Axis M4327-P | ||
Axis M4328-P | ||
Axis P1467-LE | ||
Axis P1468-XLE | ||
Axis P1468-XLE | ||
Axis P3265-LV | ||
Axis P3265-LVE | ||
Axis P3265-V | ||
Axis P3267-LV | ||
Axis P3267-LVE | ||
Axis P3268-LV | ||
Axis P3268-LVE | ||
Axis P3827-PVE | ||
Axis P4705-PLVE | ||
Axis P4707-PLVE | ||
Axis Q1656-LE | ||
Axis Q1656-B | ||
Axis Q1656-BE | ||
Axis Q1656 | ||
Axis Q1656 | ||
Axis Q1656-LE | ||
Axis Q1961-T | ||
Axis Q2101-TE | ||
Axis Q3536-LVE | ||
Axis Q3538-LVE | ||
Axis Q3626-VE | ||
Axis Q3628-VE | ||
Axis Q1656 | ||
AXIS AXIS OS | <11.6.94 | |
Axis A8207 MKII | ||
Axis Q3527-LVE | ||
All of | ||
Any of | ||
AXIS AXIS OS | >=10.11.55<10.12.206 | |
AXIS AXIS OS | >=11.0.89<11.6.94 | |
Any of | ||
Axis M3215 | ||
Axis M3216 | ||
Axis M4317-PLVE | ||
Axis M4318-PLVE | ||
Axis M4327-P | ||
Axis M4328-P | ||
Axis P1467-LE | ||
Axis P1468-XLE | ||
Axis P1468-XLE | ||
Axis P3265-LV | ||
Axis P3265-LVE | ||
Axis P3265-V | ||
Axis P3267-LV | ||
Axis P3267-LVE | ||
Axis P3268-LV | ||
Axis P3268-LVE | ||
Axis P3827-PVE | ||
Axis P4705-PLVE | ||
Axis P4707-PLVE | ||
Axis Q1656-LE | ||
Axis Q1656-B | ||
Axis Q1656-BE | ||
Axis Q1656 | ||
Axis Q1656 | ||
Axis Q1656-LE | ||
Axis Q1961-T | ||
Axis Q2101-TE | ||
Axis Q3536-LVE | ||
Axis Q3538-LVE | ||
Axis Q3626-VE | ||
Axis Q3628-VE | ||
Axis Q1656 | ||
All of | ||
AXIS AXIS OS | <11.6.94 | |
Axis A8207 MKII | ||
All of | ||
Any of | ||
AXIS AXIS OS | >=10.11.55<10.12.206 | |
AXIS AXIS OS | >=11.0.89<11.6.94 | |
Axis Q3527-LVE |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-21414 is a vulnerability found during a penetration test conducted by NCC Group on Axis Communications' Secure Boot protection for device tampering which allows a sophisticated attack to bypass this protection.
CVE-2023-21414 affects Axis Axis OS versions 10.11.55 to 10.12.206 and 11.0.89 to 11.6.94.
CVE-2023-21414 has a severity score of 6.8, which is considered high.
Yes, Axis has released a patch for CVE-2023-21414. Please refer to their official website for more information.
You can find more information about CVE-2023-21414 on Axis Communications' official website.