HIGH🇵🇱 Wersja polska

CVE-2021-31988

CVSS 8.8v3.1pub. 2021-10-05upd. 2024-11-21

A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to add the Carriage Return and Line Feed (CRLF) control characters and include arbitrary SMTP headers in the generated test email.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  • Axis Os

    OS
    Axis
    < 10.7
  • Axis Os 2016

    OS
    Axis
    < 6.50.5.5
  • Axis Os 2018

    OS
    Axis
    < 8.40.4.3
  • Axis Os 2020

    OS
    Axis
    < 9.80.3.5
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-0324CRITICAL9.4PL ✓same product

Privilege escalation w VAPIX Device Configuration Framework (Axis OS)

CVE-2023-21413CRITICAL9.1PL ✓same product

Command Injection w AXIS OS podczas instalacji aplikacji ACAP — RCE

CVE-2025-11142HIGH7.1same product

The VAPIX API mediaclip.cgi that did not have a sufficient input validation allowing for a possible remote cod...

CVE-2025-0358HIGH8.8same product

During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the ...

CVE-2025-0359HIGH8.5same product

During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the ...