CVE-2023-5800: Insufficient input validation in VAPIX API create_overlay.cgi
Vintage, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API createoverlay.cgi did not have a sufficient input validation allowing for a possible remote code execution. This flaw can only be exploited after authenticating with an operator- or administrator-privileged service account. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-5800?
CVE-2023-5800 is classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2023-5800?
To fix CVE-2023-5800, upgrade your AXIS OS to the latest version above 11.8.61, 10.12.220, or 9.80.55 for the respective affected versions.
What software is affected by CVE-2023-5800?
CVE-2023-5800 affects AXIS OS versions up to 11.8.61, 10.12.220, and 9.80.55.
Can CVE-2023-5800 be exploited without authentication?
No, CVE-2023-5800 requires authentication as either an operator or administrator to exploit.
What type of vulnerability is CVE-2023-5800?
CVE-2023-5800 is a remote code execution vulnerability due to insufficient input validation in the VAPIX API.