← Vulnerability feed

Vulnerability record · CVE-2023-21405 · published 25 July 2023

CVE-2023-21405: Axis a1001 firmware vulnerability

Axis · A1001 Firmware

Knud from Fraktal.fi has found a flaw in some Axis Network Door Controllers and Axis Network Intercoms when communicating over OSDP, highlighting that the OSDP message parser crashes the pacsiod process, causing a temporary unavailability of the door-controlling functionalities meaning that doors cannot be opened or closed. No sensitive or customer data can be extracted as the Axis device is not further compromised. Please refer to the Axis security advisory for more information, mitigation and affected products and software versions.

6.5 CVSS 3.1 Medium EPSS 0.30% · top 80.1% CWE-1286 · CWE-1286
6.5CVSS 3.1 base score
0.30%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Knud from Fraktal.fi has found a flaw in some Axis Network Door Controllers and Axis Network Intercoms when communicating over OSDP, highlighting that the OSDP message parser crashes the pacsiod process, causing a temporary unavailability of the door-controlling functionalities meaning that doors cannot be opened or closed. No sensitive or customer data can be extracted as the Axis device is not further compromised. Please refer to the Axis security advisory for more information, mitigation and affected products and software versions.

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-21405 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-10660Axis IP Cameras shell command injectionMultiple Axis IP camera models contain a shell command injection flaw (CWE-78). An unauthenticated remote attacker can inject operating system comman…EPSS 82%analysed9.8CVE-2018-10661Axis IP Cameras access control bypassMultiple models of Axis IP Cameras contain an access control bypass, as reported by the vendor and third-party researchers. The flaw allows an unauth…EPSS 87%analysed9.8CVE-2018-10662Axis IP Cameras expose insecure interface allowing remote compromiseMultiple Axis IP camera models ship with an exposed insecure interface. The flaw is remotely reachable without authentication and, per the CVSS vecto…EPSS 80%analysed8.8CVE-2026-1185Axis os incorrect permission assignment vulnerabilityA configuration file on the local file system had improper input validation which could allow code execution and potentially lead to privilege escala…EPSS 0.23%8.8CVE-2025-11142Axis os os command injection vulnerabilityThe VAPIX API mediaclip.cgi that did not have a sufficient input validation allowing for a possible remote code execution. This flaw can only be expl…EPSS 0.52%8.8CVE-2025-0324Axis os vulnerabilityThe VAPIX Device Configuration framework allowed a privilege escalation, enabling a lower-privileged user to gain administrator privileges.EPSS 0.40%8.8CVE-2025-0358Axis os improper privilege management vulnerabilityDuring an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework th…EPSS 0.25%8.8CVE-2023-5800Axis os code injection vulnerabilityVintage, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API create_overlay.cgi did not have a sufficient input validation allowin…EPSS 0.68%

Source: NIST National Vulnerability Database (record CVE-2023-21405), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.