CVE-2023-21405
Axis Communications
- Published
- 25 July 2023
- Last modified
- 17 June 2026
- CVSS
- 6.5 v3.1
- Severity
- medium
- EPSS
- 0.3% (22th pct)
- CISA KEV
- Not listed
- NVD status
- Modified
- Weaknesses
- CWE-1286, CWE-754
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Description
Knud from Fraktal.fi has found a flaw in some Axis Network Door Controllers and Axis Network Intercoms when communicating over OSDP, highlighting that the OSDP message parser crashes the pacsiod process, causing a temporary unavailability of the door-controlling functionalities meaning that doors cannot be opened or closed. No sensitive or customer data can be extracted as the Axis device is not further compromised. Please refer to the Axis security advisory for more information, mitigation and affected products and software versions.
Exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalogue as of 2026.09.04. That is an absence of confirmed public exploitation, not evidence that exploitation has not occurred. EPSS models a 0.3% probability of exploitation activity in the next 30 days.
Affected products
| Product | Vendor | Type | Versions named |
|---|---|---|---|
| A1001 | Axis Communications | unknown | < 1.65.1, <= 1.65.4 |
| A1210 (-B) | Axis Communications | unknown | <= 11.6.16.0, >= 11.0 |
| A1601 | Axis Communications | unknown | <= 1.84.4, <= 10.12.171.0, <= 11.6.16.0, >= 10.0 +1 |
| A1610 (-B) | Axis Communications | unknown | <= 10.12.171.0, <= 11.6.16.0, >= 11.0 |
| A8207 | Axis Communications | unknown | — |
| A8207 MKII | Axis Communications | unknown | — |
| Axis Os | Axis Communications | unknown | < 10.12.199, < 10.12.206, < 10.7, < 10.8 +41 |
References
Vendor advisory and patch
- https://www.axis.com/dam/public/7f/3a/ed/cve-2023-21405-en-US-407244.pdf
- https://www.axis.com/dam/public/7f/3a/ed/cve-2023-21405-en-US-407244.pdf
Record assembled from NVD, CISA KEV 2026.09.04 and FIRST EPSS 2026-09-04. Affected products are those NVD's CPE configuration names that fall inside this site's scope; a CVE may affect products outside it.