CVE-2023-21415: Axis OS

High severity, CVSS 8.1. EPSS: 0.6% chance of exploitation in the next 30 days.

Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API overlay_del.cgi is vulnerable to path traversal attacks that allows for file deletion. This flaw can only be exploited after authenticating with an operator- or administrator-privileged service account. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.

Affected products

  • Axis Axis OS: from 6.50.5.3, before 6.50.5.14 (fixed in 6.50.5.14); from 11.0.81, before 11.6.94 (fixed in 11.6.94)
  • Axis Axis OS 2016: from 6.50.2, before 6.50.5.2 (fixed in 6.50.5.2)
  • Axis Axis OS 2018: before 8.40.35 (fixed in 8.40.35)
  • Axis Axis OS 2020: before 9.80.47 (fixed in 9.80.47)
  • Axis Axis OS 2022: before 10.12.206 (fixed in 10.12.206)

Published 2023-10-16. Last modified 2026-06-17.