CVE-2023-5677

MEDIUM
Published Feb 5, 2024 Modified May 15, 2025 CWE-78 CWE-94

Description

Brandon Rothel from QED Secure Solutions and Sam Hanson of Dragos have found that the VAPIX API tcptest.cgi did not have a sufficient input validation allowing for a possible remote code execution. This flaw can only be exploited after authenticating with an operator- or administrator-privileged service account. The impact of exploiting this vulnerability is lower with operator-privileges compared to administrator-privileges service accounts. Please refer to the Axis security advisory for more information and solution.

Is your site exposed to CVE-2023-5677?

Run a free security scan — no signup, results in seconds.

CVSS v3.1 Score

6.3
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Weakness Type (CWE)

CWE-78 OS Command Injection
CWE-94 CWE-94

Affected Products

Vendor Product
axis m3024-lve_firmware
axis m3024-lve
axis m3025-ve_firmware
axis m3025-ve
axis m7014_firmware
axis m7014
axis m7016_firmware
axis m7016
axis p1214-e_firmware
axis p1214-e
axis p7214_firmware
axis p7214
axis p7216_firmware
axis p7216
axis q7401_firmware
axis q7401
axis q7404_firmware
axis q7404
axis q7414_firmware
axis q7414
axis q7424-r_mk_ii_firmware
axis q7424-r_mk_ii

References

Frequently Asked Questions

What is CVE-2023-5677? +
Brandon Rothel from QED Secure Solutions and Sam Hanson of Dragos have found that the VAPIX API tcptest.cgi did not have a sufficient input validation allowing for a possible remote code execution. This flaw can only be exploited after authenticating with an operator- or administrator-privileged service account. The impact of exploiting this vulnerability is lower with operator-privileges compared to administrator-privileges service accounts. Please refer to the Axis security advisory for more information and solution. It has a CVSS v3.1 base score of 6.3 (MEDIUM).
How severe is CVE-2023-5677? +
CVE-2023-5677 has a CVSS v3.1 score of 6.3 out of 10, rated MEDIUM. This is a medium-severity vulnerability that should be remediated as part of regular maintenance.
What products are affected by CVE-2023-5677? +
CVE-2023-5677 affects products from axis, specifically: m3024-lve, m3024-lve_firmware, m3025-ve, m3025-ve_firmware, m7014, m7014_firmware, m7016, m7016_firmware, p1214-e, p1214-e_firmware, p7214, p7214_firmware, p7216, p7216_firmware, q7401, q7401_firmware, q7404, q7404_firmware, q7414, q7414_firmware, q7424-r_mk_ii, q7424-r_mk_ii_firmware. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2023-5677? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2023-5677 — free, no signup required.