CVE-2021-31988
Last modified
CVE-2021-31988 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to add the Carriage Return and Line Feed (CRLF) control characters and include arbitrary SMTP headers in the generated test email.. EPSS estimates a 0.92% chance of exploitation in the next 30 days.
Description
A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to add the Carriage Return and Line Feed (CRLF) control characters and include arbitrary SMTP headers in the generated test email.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Axis | Axis Os | < 10.7 |
| Axis | Axis Os 2016 | < 6.50.5.5 |
| Axis | Axis Os 2018 | < 8.40.4.3 |
| Axis | Axis Os 2020 | < 9.80.3.5 |
References
- https://www.axis.com/files/tech_notes/CVE-2021-31988.pdfVendor Advisory
- https://www.axis.com/files/tech_notes/CVE-2021-31988.pdfVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-31988?
How severe is CVE-2021-31988?
How do I fix CVE-2021-31988?
Are you affected by CVE-2021-31988?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
