← Vulnerability feed

Vulnerability record · CVE-2023-21406 · published 25 July 2023

CVE-2023-21406: Axis a1001 firmware heap-based buffer overflow vulnerability

Axis · A1001 Firmware

Ariel Harush and Roy Hodir from OTORIO have found a flaw in the AXIS A1001 when communicating over OSDP. A heap-based buffer overflow was found in the pacsiod process which is handling the OSDP communication allowing to write outside of the allocated buffer. By appending invalid data to an OSDP message it was possible to write data beyond the heap allocated buffer. The data written outside the buffer could be used to execute arbitrary code.  lease refer to the Axis security advisory for more information, mitigation and affected products and software versions.

8.8 CVSS 3.1 High EPSS 0.31% · top 78.9% CWE-122 · Heap-based buffer overflowCWE-787 · Out-of-bounds write
8.8CVSS 3.1 base score
0.31%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Ariel Harush and Roy Hodir from OTORIO have found a flaw in the AXIS A1001 when communicating over OSDP. A heap-based buffer overflow was found in the pacsiod process which is handling the OSDP communication allowing to write outside of the allocated buffer. By appending invalid data to an OSDP message it was possible to write data beyond the heap allocated buffer. The data written outside the buffer could be used to execute arbitrary code.  lease refer to the Axis security advisory for more information, mitigation and affected products and software versions.

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-21406 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-10660Axis IP Cameras shell command injectionMultiple Axis IP camera models contain a shell command injection flaw (CWE-78). An unauthenticated remote attacker can inject operating system comman…EPSS 82%analysed9.8CVE-2018-10661Axis IP Cameras access control bypassMultiple models of Axis IP Cameras contain an access control bypass, as reported by the vendor and third-party researchers. The flaw allows an unauth…EPSS 87%analysed9.8CVE-2018-10662Axis IP Cameras expose insecure interface allowing remote compromiseMultiple Axis IP camera models ship with an exposed insecure interface. The flaw is remotely reachable without authentication and, per the CVSS vecto…EPSS 80%analysed7.5CVE-2018-10658Axis a1001 firmware memory buffer overflow vulnerabilityThere was a Memory Corruption issue discovered in multiple models of Axis IP Cameras which causes a denial of service (crash). The crash arises from …EPSS 1.5%7.5CVE-2018-10659Axis a1001 firmware memory buffer overflow vulnerabilityThere was a Memory Corruption issue discovered in multiple models of Axis IP Cameras which allows remote attackers to cause a denial of service (cras…EPSS 1.8%7.5CVE-2018-10663Axis a1001 firmware information exposure vulnerabilityAn issue was discovered in multiple models of Axis IP Cameras. There is an Incorrect Size Calculation.EPSS 1.5%7.5CVE-2018-10664Axis a1001 firmware memory buffer overflow vulnerabilityAn issue was discovered in the httpd process in multiple models of Axis IP Cameras. There is Memory Corruption.EPSS 1.5%6.5CVE-2023-21405Axis a1001 firmware vulnerabilityKnud from Fraktal.fi has found a flaw in some Axis Network Door Controllers and Axis Network Intercoms when communicating over OSDP, highlighting tha…EPSS 0.30%

Source: NIST National Vulnerability Database (record CVE-2023-21406), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.