Description
NCC Group has found a flaw during the annual internal penetration test ordered by Axis Communications. The protection for device tampering (commonly known as Secure Boot) contains a flaw which provides an opportunity for a sophisticated attack to bypass this protection. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.
Published: 2023-10-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-25582 NCC Group has found a flaw during the annual internal penetration test ordered by Axis Communications. The protection for device tampering (commonly known as Secure Boot) contains a flaw which provides an opportunity for a sophisticated attack to bypass this protection. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.
History

Fri, 08 Nov 2024 09:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:axis:a8207-ve_mk_ii:*:*:*:*:*:*:*:*
cpe:2.3:o:axis:axis_os:*:*:*:*:-:*:*:*
cpe:2.3:o:axis:q3527-lve:*:*:*:*:*:*:*:*
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 08 Nov 2024 08:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-121

Subscriptions

Axis A8207-ve Mk Ii Axis Os M3215 M3216 M4317-plve M4318-plve M4327-p M4328-p P1467-le P1468-le P1468-xle P3265-lv P3265-lve P3265-v P3267-lv P3267-lve P3268-lv P3268-lve P3827-pve P4705-plve P4707-plve Q1656 Q1656-b Q1656-be Q1656-ble Q1656-dle Q1656-le Q1961-te Q2101-te Q3527-lve Q3536-lve Q3538-lve Q3626-ve Q3628-ve Xfq1656
cve-icon MITRE

Status: PUBLISHED

Assigner: Axis

Published:

Updated: 2024-11-08T08:32:47.057Z

Reserved: 2022-11-04T18:30:01.767Z

Link: CVE-2023-21414

cve-icon Vulnrichment

Updated: 2024-08-02T09:36:34.410Z

cve-icon NVD

Status : Modified

Published: 2023-10-16T07:15:08.680

Modified: 2024-11-21T07:42:48.913

Link: CVE-2023-21414

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses