License Plate Verifier
by Axis
CVEs (5)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-21407 | Hig | 0.57 | 8.8 | 0.01 | Aug 3, 2023 | A broken access control was found allowing for privileged escalation of the operator account to gain administrator privileges. | ||
| CVE-2023-21409 | Hig | 0.55 | 8.4 | 0.01 | Aug 3, 2023 | Due to insufficient file permissions, unprivileged users could gain access to unencrypted administrator credentials allowing the configuration of the application. | ||
| CVE-2023-21412 | Hig | 0.47 | 7.2 | 0.01 | Aug 3, 2023 | User provided input is not sanitized on the AXIS License Plate Verifier specific “search.cgi” allowing for SQL injections. | ||
| CVE-2023-21411 | Hig | 0.47 | 7.2 | 0.01 | Aug 3, 2023 | User provided input is not sanitized in the “Settings > Access Control” configuration interface allowing for arbitrary code execution. | ||
| CVE-2023-21410 | Hig | 0.47 | 7.2 | 0.01 | Aug 3, 2023 | User provided input is not sanitized on the AXIS License Plate Verifier specific “api.cgi” allowing for arbitrary code execution. |
- risk 0.57cvss 8.8epss 0.01
A broken access control was found allowing for privileged escalation of the operator account to gain administrator privileges.
- risk 0.55cvss 8.4epss 0.01
Due to insufficient file permissions, unprivileged users could gain access to unencrypted administrator credentials allowing the configuration of the application.
- risk 0.47cvss 7.2epss 0.01
User provided input is not sanitized on the AXIS License Plate Verifier specific “search.cgi” allowing for SQL injections.
- risk 0.47cvss 7.2epss 0.01
User provided input is not sanitized in the “Settings > Access Control” configuration interface allowing for arbitrary code execution.
- risk 0.47cvss 7.2epss 0.01
User provided input is not sanitized on the AXIS License Plate Verifier specific “api.cgi” allowing for arbitrary code execution.