NCC Group has found a flaw during the annual internal penetration test ordered by Axis Communications. The protection for device tampering (commonly known as Secure Boot) contains a flaw which provides an opportunity for a sophisticated attack to bypass this protection. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.
Subscriptions
| Vendors | Products |
|---|---|
|
Axis
Subscribe
|
A8207-ve Mk Ii
Subscribe
Axis Os
Subscribe
M3215
Subscribe
M3216
Subscribe
M4317-plve
Subscribe
M4318-plve
Subscribe
M4327-p
Subscribe
M4328-p
Subscribe
P1467-le
Subscribe
P1468-le
Subscribe
P1468-xle
Subscribe
P3265-lv
Subscribe
P3265-lve
Subscribe
P3265-v
Subscribe
P3267-lv
Subscribe
P3267-lve
Subscribe
P3268-lv
Subscribe
P3268-lve
Subscribe
P3827-pve
Subscribe
P4705-plve
Subscribe
P4707-plve
Subscribe
Q1656
Subscribe
Q1656-b
Subscribe
Q1656-be
Subscribe
Q1656-ble
Subscribe
Q1656-dle
Subscribe
Q1656-le
Subscribe
Q1961-te
Subscribe
Q2101-te
Subscribe
Q3527-lve
Subscribe
Q3536-lve
Subscribe
Q3538-lve
Subscribe
Q3626-ve
Subscribe
Q3628-ve
Subscribe
Xfq1656
Subscribe
|
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-25582 | NCC Group has found a flaw during the annual internal penetration test ordered by Axis Communications. The protection for device tampering (commonly known as Secure Boot) contains a flaw which provides an opportunity for a sophisticated attack to bypass this protection. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 08 Nov 2024 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:o:axis:a8207-ve_mk_ii:*:*:*:*:*:*:*:* cpe:2.3:o:axis:axis_os:*:*:*:*:-:*:*:* cpe:2.3:o:axis:q3527-lve:*:*:*:*:*:*:*:* |
|
| Metrics |
ssvc
|
Fri, 08 Nov 2024 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-121 |
Status: PUBLISHED
Assigner: Axis
Published:
Updated: 2024-11-08T08:32:47.057Z
Reserved: 2022-11-04T18:30:01.767Z
Link: CVE-2023-21414
Updated: 2024-08-02T09:36:34.410Z
Status : Modified
Published: 2023-10-16T07:15:08.680
Modified: 2024-11-21T07:42:48.913
Link: CVE-2023-21414
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD