« Back to list

CVE-2023-21414

Status: ModifiedMedium (6.8)—

NCC Group has found a flaw during the annual internal penetration test ordered by Axis Communications. The protection for device tampering (commonly known as Secure Boot) contains a flaw which provides an opportunity for a sophisticated attack to bypass this protection. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2023-21414",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-21414",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-09-16T17:32:46.140128Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "product-security@axis.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 7.1,
          "attackVector": "PHYSICAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 0.5
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.8,
          "attackVector": "PHYSICAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 0.9
      }
    ]
  },
  "affected": [
    {
      "source": "product-security@axis.com",
      "affectedData": [
        {
          "vendor": "Axis Communications AB",
          "product": "AXIS OS",
          "versions": [
            {
              "status": "affected",
              "version": "AXIS OS 10.11 - 11.5"
            }
          ],
          "platforms": [
            "ARTPEC 8"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Axis Communications AB",
          "product": "AXIS A8207-VE Mk II",
          "versions": [
            {
              "status": "affected",
              "version": "AXIS OS 11.5 or earlier"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Axis Communications AB",
          "product": "AXIS Q3527-LVE",
          "versions": [
            {
              "status": "affected",
              "version": "AXIS OS 10.11 - 11.5"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:o:axis:axis_os:*:*:*:*:-:*:*:*"
          ],
          "vendor": "axis",
          "product": "axis_os",
          "versions": [
            {
              "status": "affected",
              "version": "10.11",
              "versionType": "custom",
              "lessThanOrEqual": "11.5"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:o:axis:a8207-ve_mk_ii:*:*:*:*:*:*:*:*"
          ],
          "vendor": "axis",
          "product": "a8207-ve_mk_ii",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "11.5",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:o:axis:q3527-lve:*:*:*:*:*:*:*:*"
          ],
          "vendor": "axis",
          "product": "q3527-lve",
          "versions": [
            {
              "status": "affected",
              "version": "10.11",
              "versionType": "custom",
              "lessThanOrEqual": "11.5"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2023-10-16T07:15:08.680",
  "references": [
    {
      "url": "https://www.axis.com/dam/public/45/3c/a1/cve-2023-21414pdf-en-US-412758.pdf",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "product-security@axis.com"
    },
    {
      "url": "https://www.axis.com/dam/public/45/3c/a1/cve-2023-21414pdf-en-US-412758.pdf",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "product-security@axis.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-121"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "NCC Group has found a flaw during the annual internal penetration test ordered by Axis Communications. The protection for device tampering (commonly known as Secure Boot) contains a flaw which provides an opportunity for a sophisticated attack to bypass this protection. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution."
    },
    {
      "lang": "es",
      "value": "NCC Group ha encontrado una falla durante la prueba de penetración interna anual solicitada por Axis Communications. La protección contra la manipulación de dispositivos (comúnmente conocida como Arranque Seguro) contiene una falla que brinda la oportunidad de que un ataque sofisticado eluda esta protección. Axis ha lanzado versiones parcheadas del Sistema Operativo AXIS para la falla resaltada. Consulte el aviso de seguridad de Axis para obtener más información y soluciones."
    }
  ],
  "lastModified": "2026-06-17T05:32:32.753",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:axis:axis_os:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A57EAA0B-F777-491D-8CA0-3946AE128F8A",
              "versionEndExcluding": "10.12.206",
              "versionStartIncluding": "10.11.55"
            },
            {
              "criteria": "cpe:2.3:o:axis:axis_os:*:*:*:*:active:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "90BE6B96-8C89-4EAC-BAA8-A1D5C1D51648",
              "versionEndExcluding": "11.6.94",
              "versionStartIncluding": "11.0.89"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:axis:m3215:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "CCF92600-C422-4EAD-9832-59940D509E35"
            },
            {
              "criteria": "cpe:2.3:h:axis:m3216:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "2FD56A2A-788C-4168-AFF8-403D0CDEB056"
            },
            {
              "criteria": "cpe:2.3:h:axis:m4317-plve:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "FF3E4C56-DF16-4954-BFAB-B877B417DC67"
            },
            {
              "criteria": "cpe:2.3:h:axis:m4318-plve:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "CEBA6BAB-84F8-4990-9F69-D2164AA41413"
            },
            {
              "criteria": "cpe:2.3:h:axis:m4327-p:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "D2A8EB07-E3C5-4752-ACF1-42A34CF8481C"
            },
            {
              "criteria": "cpe:2.3:h:axis:m4328-p:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "1CD842CE-5408-4DC3-8047-4E3A55B1253C"
            },
            {
              "criteria": "cpe:2.3:h:axis:p1467-le:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A678D824-2504-4C95-910D-3EE27F71278B"
            },
            {
              "criteria": "cpe:2.3:h:axis:p1468-le:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "33BA6000-C024-4B45-8449-ADE57233B593"
            },
            {
              "criteria": "cpe:2.3:h:axis:p1468-xle:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "6313E41C-6087-437D-9AE9-73A853EE4C48"
            },
            {
              "criteria": "cpe:2.3:h:axis:p3265-lv:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "52E2F23C-D61D-4A40-B9F9-7DE0740A743D"
            },
            {
              "criteria": "cpe:2.3:h:axis:p3265-lve:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "8E96AFC9-5D17-469E-A120-F8D25BA3D3A2"
            },
            {
              "criteria": "cpe:2.3:h:axis:p3265-v:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "4A761F9E-DDEB-43B5-BE2D-54B1BD3207DB"
            },
            {
              "criteria": "cpe:2.3:h:axis:p3267-lv:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "4724987B-2077-4598-B179-ECAAD3646793"
            },
            {
              "criteria": "cpe:2.3:h:axis:p3267-lve:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "68DC7D03-7348-4641-8109-A610D8F586DF"
            },
            {
              "criteria": "cpe:2.3:h:axis:p3268-lv:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "E8457180-29F6-4742-A1C8-EFB3D511B6EC"
            },
            {
              "criteria": "cpe:2.3:h:axis:p3268-lve:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "0B022EF0-E531-4F82-8E03-B46414555A9A"
            },
            {
              "criteria": "cpe:2.3:h:axis:p3827-pve:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "8E566446-B3C7-4D03-9FA5-D999C10183B0"
            },
            {
              "criteria": "cpe:2.3:h:axis:p4705-plve:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "E0624855-756A-40A9-91BF-DE8C0EC355D6"
            },
            {
              "criteria": "cpe:2.3:h:axis:p4707-plve:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "E10F52AE-C6D7-4E10-B496-18CCF617FB69"
            },
            {
              "criteria": "cpe:2.3:h:axis:q1656:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "74D4E995-4C85-4E94-B18B-044C6D95490C"
            },
            {
              "criteria": "cpe:2.3:h:axis:q1656-b:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "68062F65-BAF1-45CC-8515-9747C6FDF42B"
            },
            {
              "criteria": "cpe:2.3:h:axis:q1656-be:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "B9D52CD5-4E62-4B7F-81B1-7A37620BEABF"
            },
            {
              "criteria": "cpe:2.3:h:axis:q1656-ble:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "985DA048-28F6-413D-A611-297993B178BE"
            },
            {
              "criteria": "cpe:2.3:h:axis:q1656-dle:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "76D5EF68-F3F3-4ABD-A139-D1823CE0F92C"
            },
            {
              "criteria": "cpe:2.3:h:axis:q1656-le:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "D1129AC4-1953-4B50-90CC-50D2E4D9AB39"
            },
            {
              "criteria": "cpe:2.3:h:axis:q1961-te:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "BBDE1252-B9A9-4876-9BA3-5D1AFB5B2E72"
            },
            {
              "criteria": "cpe:2.3:h:axis:q2101-te:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "D5C9586E-9B12-4C45-9F89-A6116493D4DE"
            },
            {
              "criteria": "cpe:2.3:h:axis:q3536-lve:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "86575D32-774E-4611-87B3-5B3A3A4B59AA"
            },
            {
              "criteria": "cpe:2.3:h:axis:q3538-lve:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "9EF429DC-1F90-4942-9A97-F93AEF866B0B"
            },
            {
              "criteria": "cpe:2.3:h:axis:q3626-ve:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "989BC60B-79F9-4650-AAA2-4787D6477B1C"
            },
            {
              "criteria": "cpe:2.3:h:axis:q3628-ve:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "0374F956-C9D1-4D9B-AEEA-4F1103EAA9CA"
            },
            {
              "criteria": "cpe:2.3:h:axis:xfq1656:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "C60CBB3A-0242-4AE7-909E-37EF99C6E136"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:axis:axis_os:*:*:*:*:active:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1F2CD512-C82D-454A-B322-BBD93EF7E85C",
              "versionEndExcluding": "11.6.94"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:axis:a8207-ve_mk_ii:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "CB61500A-D634-436C-8BE9-00CEEC301B55"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:axis:axis_os:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A57EAA0B-F777-491D-8CA0-3946AE128F8A",
              "versionEndExcluding": "10.12.206",
              "versionStartIncluding": "10.11.55"
            },
            {
              "criteria": "cpe:2.3:o:axis:axis_os:*:*:*:*:active:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "90BE6B96-8C89-4EAC-BAA8-A1D5C1D51648",
              "versionEndExcluding": "11.6.94",
              "versionStartIncluding": "11.0.89"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:axis:q3527-lve:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "7C7601D7-8413-49DF-AFCC-1C7851A1B41A"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "product-security@axis.com"
}