VYPR
Medium severity5.3NVD Advisory· Published Aug 25, 2021· Updated Jun 17, 2026

CVE-2021-31989

CVE-2021-31989

Description

A user with permission to log on to the machine hosting the AXIS Device Manager client could under certain conditions extract a memory dump from the built-in Windows Task Manager application. The memory dump may potentially contain credentials of connected Axis devices.

Affected products

3
  • cpe:2.3:a:axis:device_manager:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:axis:device_manager:*:*:*:*:*:*:*:*range: >=5.00.010,<=5.16.063
    • (no CPE)
  • Axis Communications AB/AXIS Device Managerv5
    Range: From Axis Device Manager 5.00.010

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.