Vulnerability Description
Brandon Rothel from QED Secure Solutions and Sam Hanson of Dragos have found that the VAPIX API tcptest.cgi did not have a sufficient input validation allowing for a possible remote code execution. This flaw can only be exploited after authenticating with an operator- or administrator-privileged service account. The impact of exploiting this vulnerability is lower with operator-privileges compared to administrator-privileges service accounts. Please refer to the Axis security advisory for more information and solution.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Axis | M3024-Lve Firmware | < 5.51.7.7 |
| Axis | M3024-Lve | - |
| Axis | M3025-Ve Firmware | < 5.51.7.7 |
| Axis | M3025-Ve | - |
| Axis | M7014 Firmware | < 5.51.7.7 |
| Axis | M7014 | - |
| Axis | M7016 Firmware | < 5.51.7.7 |
| Axis | M7016 | - |
| Axis | P1214-E Firmware | < 5.51.7.7 |
| Axis | P1214-E | - |
| Axis | P7214 Firmware | < 5.51.7.7 |
| Axis | P7214 | - |
| Axis | P7216 Firmware | < 5.51.7.7 |
| Axis | P7216 | - |
| Axis | Q7401 Firmware | < 5.51.7.7 |
| Axis | Q7401 | - |
| Axis | Q7404 Firmware | < 5.51.7.7 |
| Axis | Q7404 | - |
| Axis | Q7414 Firmware | < 5.51.7.7 |
| Axis | Q7414 | - |
Related Weaknesses (CWE)
References
- https://www.axis.com/dam/public/0a/47/d1/cve-2023-5677-en-US-483444.pdf
- https://www.axis.com/dam/public/a9/dd/f1/cve-2023-5677-en-US-424335.pdfVendor Advisory
FAQ
What is CVE-2023-5677?
CVE-2023-5677 is a vulnerability with a CVSS score of 6.3 (MEDIUM). Brandon Rothel from QED Secure Solutions and Sam Hanson of Dragos have found that the VAPIX API tcptest.cgi did not have a sufficient input validation allowing for a possible remote code execution. Th...
How severe is CVE-2023-5677?
CVE-2023-5677 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-5677?
Check the references section above for vendor advisories and patch information. Affected products include: Axis M3024-Lve Firmware, Axis M3024-Lve, Axis M3025-Ve Firmware, Axis M3025-Ve, Axis M7014 Firmware.