MEDIUM · 6.3

CVE-2023-5677

Brandon Rothel from QED Secure Solutions and Sam Hanson of Dragos have found that the VAPIX API tcptest.cgi did not have a sufficient input validation allowing for a possible remote code execution. Th...

Vulnerability Description

Brandon Rothel from QED Secure Solutions and Sam Hanson of Dragos have found that the VAPIX API tcptest.cgi did not have a sufficient input validation allowing for a possible remote code execution. This flaw can only be exploited after authenticating with an operator- or administrator-privileged service account. The impact of exploiting this vulnerability is lower with operator-privileges compared to administrator-privileges service accounts. Please refer to the Axis security advisory for more information and solution.

CVSS Score

6.3

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
LOW
Availability
LOW

Affected Products

VendorProductVersions
AxisM3024-Lve Firmware< 5.51.7.7
AxisM3024-Lve-
AxisM3025-Ve Firmware< 5.51.7.7
AxisM3025-Ve-
AxisM7014 Firmware< 5.51.7.7
AxisM7014-
AxisM7016 Firmware< 5.51.7.7
AxisM7016-
AxisP1214-E Firmware< 5.51.7.7
AxisP1214-E-
AxisP7214 Firmware< 5.51.7.7
AxisP7214-
AxisP7216 Firmware< 5.51.7.7
AxisP7216-
AxisQ7401 Firmware< 5.51.7.7
AxisQ7401-
AxisQ7404 Firmware< 5.51.7.7
AxisQ7404-
AxisQ7414 Firmware< 5.51.7.7
AxisQ7414-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-5677?

CVE-2023-5677 is a vulnerability with a CVSS score of 6.3 (MEDIUM). Brandon Rothel from QED Secure Solutions and Sam Hanson of Dragos have found that the VAPIX API tcptest.cgi did not have a sufficient input validation allowing for a possible remote code execution. Th...

How severe is CVE-2023-5677?

CVE-2023-5677 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-5677?

Check the references section above for vendor advisories and patch information. Affected products include: Axis M3024-Lve Firmware, Axis M3024-Lve, Axis M3025-Ve Firmware, Axis M3025-Ve, Axis M7014 Firmware.