CVE-2023-21404: Axis OS

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

AXIS OS 11.0.X - 11.3.x use a static RSA key in legacy LUA-components to protect Axis-specific source code. The static RSA key is not used in any other secure communication nor can it be used to compromise the device or any customer data.

Affected products

  • Axis Axis OS: from 11.0.89, before 11.4.52 (fixed in 11.4.52)

Published 2023-05-08. Last modified 2026-06-17.