7.5

CVE-2021-31987

A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to bypass blocked network recipients.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Axis ≫ Axis Os SwEdition active Version < 10.8
Axis ≫ Axis Os 2016 SwEdition lts Version < 6.50.5.5
Axis ≫ Axis Os 2018 SwEdition lts Version < 8.40.4.3
Axis ≫ Axis Os 2020 SwEdition lts Version < 9.80.3.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.89% 0.558
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 1.6 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
NIST 5.1 4.9 6.4
AV:N/AC:H/Au:N/C:P/I:P/A:P
CWE-1286 Improper Validation of Syntactic Correctness of Input

The product receives input that is expected to be well-formed - i.e., to comply with a certain syntax - but it does not validate or incorrectly validates that the input complies with the syntax.

https://www.axis.com/files/tech_notes/CVE-2021-31987.pdf
Vendor Advisory