CVE-2023-21404
Severity CVSS v4.0:
Pending analysis
Type:
CWE-321
Use of Hard-coded Cryptographic Key
Publication date:
08/05/2023
Last modified:
29/01/2025
Description
AXIS OS 11.0.X - 11.3.x use a static RSA key in legacy LUA-components to protect Axis-specific source code. The static RSA key is not used in any other secure communication nor can it be used to compromise the device or any customer data.
Impact
Base Score 3.x
5.30
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:axis:axis_os:*:*:*:*:-:*:*:* | 11.0.89 (including) | 11.4.52 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



