CVSS 3.1 Score 7.1 of 10 (high)


Published Nov 21, 2023
Updated: Nov 28, 2023


CVE-2023-21416 refers to a vulnerability discovered by Sandro Poppi in the VAPIX API dynamicoverlay.cgi of Axis devices. This vulnerability allows for a Denial-of-Service attack, which can block access to the overlay configuration page in the web interface of the affected devices. The flaw can only be exploited after authenticating with an operator- or administrator-privileged service account. Axis has released patched versions of AXIS OS to address this vulnerability, and organizations are advised to refer to the Axis security advisory for more information on how to remediate it. The potential danger posed by this vulnerability is considered high, with a base severity rating of 7.1 and an availability impact score of 4.2 out of 10.

Explore Beyond the CVE Basics with Recorded Future's Vulnerability Intelligence

Note: This is just a basic overview providing quick insights into CVE-2023-21416 information. Gain full access to comprehensive CVE data, risk scores, prioritization, and mitigation data through Recorded Future's Vulnerability Intelligence:
  • Prioritize with Risk-Based Scoring
  • Explore the Extensive Vulnerability Database
  • Receive Early Alerts on Emerging CVEs
  • Focus on Critical Exploitable Vulnerabilities
  • Streamline Remediation with Integration Options