CVE-2021-31988 Vulnerability Details

  /     /     /  

CVE-2021-31988 Metadata Quick Info

CVE Published: 05/10/2021 | CVE Updated: 08/11/2024 | CVE Year: 2021
Source: Axis | Vendor: Axis Communications AB | Product: AXIS OS
Status : PUBLISHED

CVE-2021-31988 Description

A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to add the Carriage Return and Line Feed (CRLF) control characters and include arbitrary SMTP headers in the generated test email.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-1286
CWE Name: CWE-1286: Improper Validation of Syntactic Correctness of Input
Source: Axis Communications AB

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).