First published: Mon Oct 16 2023(Updated: )
NCC Group has found a flaw during the annual internal penetration test ordered by Axis Communications. The protection for device tampering (commonly known as Secure Boot) contains a flaw which provides an opportunity for a sophisticated attack to bypass this protection. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.
Credit: product-security@axis.com product-security@axis.com
Affected Software | Affected Version | How to fix |
---|---|---|
Axis Axis Os | >=10.11.55<10.12.206 | |
Axis Axis Os | >=11.0.89<11.6.94 | |
Axis M3215 | ||
Axis M3216 | ||
Axis M4317-plve | ||
Axis M4318-plve | ||
Axis M4327-p | ||
Axis M4328-p | ||
Axis P1467-le | ||
Axis P1468-le | ||
Axis P1468-xle | ||
Axis P3265-lv | ||
Axis P3265-lve | ||
Axis P3265-v | ||
Axis P3267-lv | ||
Axis P3267-lve | ||
Axis P3268-lv | ||
Axis P3268-lve | ||
Axis P3827-pve | ||
Axis P4705-plve | ||
Axis P4707-plve | ||
Axis Q1656 | ||
Axis Q1656-b | ||
Axis Q1656-be | ||
Axis Q1656-ble | ||
Axis Q1656-dle | ||
Axis Q1656-le | ||
Axis Q1961-te | ||
Axis Q2101-te | ||
Axis Q3536-lve | ||
Axis Q3538-lve | ||
Axis Q3626-ve | ||
Axis Q3628-ve | ||
Axis Xfq1656 | ||
Axis Axis Os | <11.6.94 | |
Axis A8207-ve Mk Ii | ||
Axis Q3527-lve | ||
All of | ||
Any of | ||
Axis Axis Os | >=10.11.55<10.12.206 | |
Axis Axis Os | >=11.0.89<11.6.94 | |
Any of | ||
Axis M3215 | ||
Axis M3216 | ||
Axis M4317-plve | ||
Axis M4318-plve | ||
Axis M4327-p | ||
Axis M4328-p | ||
Axis P1467-le | ||
Axis P1468-le | ||
Axis P1468-xle | ||
Axis P3265-lv | ||
Axis P3265-lve | ||
Axis P3265-v | ||
Axis P3267-lv | ||
Axis P3267-lve | ||
Axis P3268-lv | ||
Axis P3268-lve | ||
Axis P3827-pve | ||
Axis P4705-plve | ||
Axis P4707-plve | ||
Axis Q1656 | ||
Axis Q1656-b | ||
Axis Q1656-be | ||
Axis Q1656-ble | ||
Axis Q1656-dle | ||
Axis Q1656-le | ||
Axis Q1961-te | ||
Axis Q2101-te | ||
Axis Q3536-lve | ||
Axis Q3538-lve | ||
Axis Q3626-ve | ||
Axis Q3628-ve | ||
Axis Xfq1656 | ||
All of | ||
Axis Axis Os | <11.6.94 | |
Axis A8207-ve Mk Ii | ||
All of | ||
Any of | ||
Axis Axis Os | >=10.11.55<10.12.206 | |
Axis Axis Os | >=11.0.89<11.6.94 | |
Axis Q3527-lve |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-21414 is a vulnerability found during a penetration test conducted by NCC Group on Axis Communications' Secure Boot protection for device tampering which allows a sophisticated attack to bypass this protection.
CVE-2023-21414 affects Axis Axis OS versions 10.11.55 to 10.12.206 and 11.0.89 to 11.6.94.
CVE-2023-21414 has a severity score of 6.8, which is considered high.
Yes, Axis has released a patch for CVE-2023-21414. Please refer to their official website for more information.
You can find more information about CVE-2023-21414 on Axis Communications' official website.