CVE-2021-31989
25.08.2021, 19:15
A user with permission to log on to the machine hosting the AXIS Device Manager client could under certain conditions extract a memory dump from the built-in Windows Task Manager application. The memory dump may potentially contain credentials of connected Axis devices.Enginsight
Vendor | Product | Version |
---|---|---|
axis | device_manager | 5.00.010 ≤ 𝑥 ≤ 5.16.063 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-316 - Cleartext Storage of Sensitive Information in MemoryThe application stores sensitive information in cleartext in memory.
- CWE-312 - Cleartext Storage of Sensitive InformationThe product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.