9.8
CVE-2023-21409
- EPSS 0.13%
- Veröffentlicht 03.08.2023 07:15:12
- Zuletzt bearbeitet 21.11.2024 07:42:48
- Quelle product-security@axis.com
- Teams Watchlist Login
- Unerledigt Login
Due to insufficient file permissions, unprivileged users could gain access to unencrypted administrator credentials allowing the configuration of the application.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Axis ≫ License Plate Verifier Version <= 2.8.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.13% | 0.338 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
product-security@axis.com | 8.4 | 2.5 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-755 Improper Handling of Exceptional Conditions
The product does not handle or incorrectly handles an exceptional condition.