CVE-2023-21405
Summary
| CVE | CVE-2023-21405 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-07-25 08:15:00 UTC |
| Updated | 2023-08-02 18:43:00 UTC |
| Description | Knud from Fraktal.fi has found a flaw in some Axis Network Door Controllers and Axis Network Intercoms when communicating over OSDP, highlighting that the OSDP message parser crashes the pacsiod process, causing a temporary unavailability of the door-controlling functionalities meaning that doors cannot be opened or closed. No sensitive or customer data can be extracted as the Axis device is not further compromised. Please refer to the Axis security advisory for more information, mitigation and affected products and software versions. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Axis | A1001 | - | All | All | All |
| Operating System | Axis | A1001 Firmware | All | All | All | All |
| Hardware | Axis | A1210 -b | - | All | All | All |
| Operating System | Axis | A1210 -b Firmware | All | All | All | All |
| Hardware | Axis | A1601 | - | All | All | All |
| Operating System | Axis | A1601 Firmware | All | All | All | All |
| Operating System | Axis | A1601 Firmware | All | All | All | All |
| Operating System | Axis | A1601 Firmware | All | All | All | All |
| Hardware | Axis | A1610 -b | - | All | All | All |
| Operating System | Axis | A1610 -b Firmware | All | All | All | All |
| Operating System | Axis | A1610 -b Firmware | All | All | All | All |
| Hardware | Axis | A8207 | - | All | All | All |
| Hardware | Axis | A8207 Mkii | - | All | All | All |
| Operating System | Axis | Axis Os | All | All | All | All |
| Operating System | Axis | Axis Os | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.axis.com/dam/public/7f/3a/ed/cve-2023-21405-en-US-407244.pdf | MISC | www.axis.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.