← Vulnerability feed

Vulnerability record · CVE-2023-21417 · published 21 November 2023

CVE-2023-21417: Axis os path traversal vulnerability

Axis · Axis Os

Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API manageoverlayimage.cgi was vulnerable to path traversal attacks that allows for file/folder deletion. This flaw can only be exploited after authenticating with an operator- or administrator- privileged service account. The impact of exploiting this vulnerability is lower with operator service accounts and limited to non-system files compared to administrator-privileges. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.

7.1 CVSS 3.1 High EPSS 0.67% · top 50.1% CWE-35 · CWE-35CWE-22 · Path traversal
7.1CVSS 3.1 base score
0.67%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API manageoverlayimage.cgi was vulnerable to path traversal attacks that allows for file/folder deletion. This flaw can only be exploited after authenticating with an operator- or administrator- privileged service account. The impact of exploiting this vulnerability is lower with operator service accounts and limited to non-system files compared to administrator-privileges. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-21417 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2026-1185Axis os incorrect permission assignment vulnerabilityA configuration file on the local file system had improper input validation which could allow code execution and potentially lead to privilege escala…EPSS 0.23%8.8CVE-2025-11142Axis os os command injection vulnerabilityThe VAPIX API mediaclip.cgi that did not have a sufficient input validation allowing for a possible remote code execution. This flaw can only be expl…EPSS 0.52%8.8CVE-2025-0324Axis os vulnerabilityThe VAPIX Device Configuration framework allowed a privilege escalation, enabling a lower-privileged user to gain administrator privileges.EPSS 0.40%8.8CVE-2025-0358Axis os improper privilege management vulnerabilityDuring an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework th…EPSS 0.25%8.8CVE-2023-5800Axis os code injection vulnerabilityVintage, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API create_overlay.cgi did not have a sufficient input validation allowin…EPSS 0.68%8.8CVE-2021-31988Axis os injection vulnerabilityA user controlled parameter related to SMTP test functionality is not correctly validated making it possible to add the Carriage Return and Line Feed…EPSS 0.95%8.1CVE-2023-21415Axis os path traversal vulnerabilitySandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API overlay_del.cgi is vulnerable to path traversal attacks that all…EPSS 0.59%7.8CVE-2025-0360Axis os incorrect authorization vulnerabilityDuring an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework th…EPSS 0.15%

Source: NIST National Vulnerability Database (record CVE-2023-21417), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.