CVE-2021-31989

Severity CVSS v4.0:
Pending analysis
Type:
CWE-312 Cleartext Storage of Sensitive Information
Publication date:
25/08/2021
Last modified:
08/11/2024

Description

A user with permission to log on to the machine hosting the AXIS Device Manager client could under certain conditions extract a memory dump from the built-in Windows Task Manager application. The memory dump may potentially contain credentials of connected Axis devices.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:axis:device_manager:*:*:*:*:*:*:*:* 5.00.010 (including) 5.16.063 (including)


References to Advisories, Solutions, and Tools