CVE-2021-31988
Published on: 10/05/2021 12:00:00 AM UTC
Last Modified on: 07/12/2022 05:42:00 PM UTC
Certain versions of Axis Os from Axis contain the following vulnerability:
A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to add the Carriage Return and Line Feed (CRLF) control characters and include arbitrary SMTP headers in the generated test email.
- CVE-2021-31988 has been assigned by
product-se[email protected] to track the vulnerability - currently rated as HIGH severity.
CVSS3 Score: 8.8 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 6.8 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | MEDIUM | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | PARTIAL | PARTIAL |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
www.axis.com application/pdf |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Operating System | Axis | Axis Os | All | All | All | All |
Operating System | Axis | Axis Os 2016 | All | All | All | All |
Operating System | Axis | Axis Os 2018 | All | All | All | All |
Operating System | Axis | Axis Os 2020 | All | All | All | All |
- cpe:2.3:o:axis:axis_os:*:*:*:*:active:*:*:*:
- cpe:2.3:o:axis:axis_os_2016:*:*:*:*:lts:*:*:*:
- cpe:2.3:o:axis:axis_os_2018:*:*:*:*:lts:*:*:*:
- cpe:2.3:o:axis:axis_os_2020:*:*:*:*:lts:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2021-31988 A user controlled parameter related to SMTP test functionality is not correctly validated making it… twitter.com/i/web/status/1… | 2021-10-06 07:10:02 |
![]() |
Nozomi found three new vulnerabilities (CVE-2021-31986, CVE-2021-31987, CVE-2021-31988) affecting all Axis devices… twitter.com/i/web/status/1… | 2021-10-06 09:59:39 |
![]() |
「3つのバグ(CVE-2021-31986、CVE-2021-31987、CVE-2021-31988)が、会社の組み込みAxisOSを実行するすべてのAxisデバイスに影響を与えることが判明した」 「Axis GearのIP監… twitter.com/i/web/status/1… | 2021-10-06 21:17:37 |