CVE-2023-21404
EUVD-2023-2557208.05.2023, 21:15
AXIS OS 11.0.X - 11.3.x use a static RSA key in legacy LUA-components to protect Axis-specific source code. The static RSA key is not used in any other secure communication nor can it be used to compromise the device or any customer data.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| axis | axis_os | 11.0.89 ≤ 𝑥 < 11.4.52 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-321 - Use of Hard-coded Cryptographic KeyThe use of a hard-coded cryptographic key significantly increases the possibility that encrypted data may be recovered.
- CWE-311 - Missing Encryption of Sensitive DataThe software does not encrypt sensitive or critical information before storage or transmission.