VYPR
Unrated severityNVD Advisory· Published Oct 16, 2023· Updated Nov 8, 2024

CVE-2023-21414

CVE-2023-21414

Description

NCC Group has found a flaw during the annual internal penetration test ordered by Axis Communications. The protection for device tampering (commonly known as Secure Boot) contains a flaw which provides an opportunity for a sophisticated attack to bypass this protection. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.

Affected products

4
  • Axis/Axis OSllm-fuzzy
  • Axis Communications AB/AXIS A8207-VE Mk IIv5
    Range: AXIS OS 11.5 or earlier
  • Axis Communications AB/AXIS OSv5
    Range: AXIS OS 10.11 - 11.5
  • Axis Communications AB/AXIS Q3527-LVEv5
    Range: AXIS OS 10.11 - 11.5

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.