CVE-2023-21415: Axis OS
High severity, CVSS 8.1. EPSS: 0.6% chance of exploitation in the next 30 days.
Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API overlay_del.cgi is vulnerable to path traversal attacks that allows for file deletion. This flaw can only be exploited after authenticating with an operator- or administrator-privileged service account. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.
Affected products
- Axis Axis OS: from 6.50.5.3, before 6.50.5.14 (fixed in 6.50.5.14); from 11.0.81, before 11.6.94 (fixed in 11.6.94)
- Axis Axis OS 2016: from 6.50.2, before 6.50.5.2 (fixed in 6.50.5.2)
- Axis Axis OS 2018: before 8.40.35 (fixed in 8.40.35)
- Axis Axis OS 2020: before 9.80.47 (fixed in 9.80.47)
- Axis Axis OS 2022: before 10.12.206 (fixed in 10.12.206)
Published 2023-10-16. Last modified 2026-06-17.