VYPR
Medium severity6.5NVD Advisory· Published Oct 16, 2023· Updated Jun 17, 2026

CVE-2023-21415

CVE-2023-21415

Description

Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API overlay_del.cgi is vulnerable to path traversal attacks that allows for file deletion. This flaw can only be exploited after authenticating with an operator- or administrator-privileged service account. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.

Affected products

8
  • Axis/AXIS OS4 versions
    cpe:2.3:o:axis:axis_os:*:*:*:*:-:*:*:*+ 3 more
    • cpe:2.3:o:axis:axis_os:*:*:*:*:-:*:*:*range: >=6.50.5.3,<6.50.5.14
    • cpe:2.3:o:axis:axis_os:*:*:*:*:active:*:*:*range: >=11.0.81,<11.6.94
    • (no CPE)
    • (no CPE)range: AXIS OS 6.50 – 11.5
  • cpe:2.3:o:axis:axis_os_2016:*:*:*:*:lts:*:*:*
    Range: >=6.50.2,<6.50.5.2
  • cpe:2.3:o:axis:axis_os_2018:*:*:*:*:lts:*:*:*
    Range: <8.40.35
  • cpe:2.3:o:axis:axis_os_2020:*:*:*:*:lts:*:*:*
    Range: <9.80.47
  • cpe:2.3:o:axis:axis_os_2022:*:*:*:*:lts:*:*:*
    Range: <10.12.206

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.