CVE-2023-21406

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
25/07/2023
Last modified:
08/11/2024

Description

Ariel Harush and Roy Hodir from OTORIO have found a flaw in the AXIS A1001 when<br /> communicating over OSDP. A heap-based buffer overflow was found in the pacsiod process which<br /> is handling the OSDP communication allowing to write outside of the allocated buffer. By<br /> appending invalid data to an OSDP message it was possible to write data beyond the heap<br /> allocated buffer. The data written outside the buffer could be used to execute arbitrary code. <br /> <br /> lease refer to the Axis security advisory for more information, mitigation and affected products and software versions.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:axis:a1001_firmware:*:*:*:*:*:*:*:* 1.65.4 (including)
cpe:2.3:h:axis:a1001:-:*:*:*:*:*:*:*