Back to Database
Status published
Unknown
CVE-2023-21404
AXIS OS 11.0.X - 11.3.x use a static RSA key...
Vulnerability Description
AXIS OS 11.0.X - 11.3.x use a static RSA key in legacy LUA-components to protect Axis-specific source code. The static RSA key is not used in any other secure communication nor can it be used to compromise the device or any customer data.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-21404
Credits & Attribution
No credits recorded in the NVD database.
More from Axis Communications AB
View All →CVE-2025-9524
The VAPIX API port.cgi did not have sufficient input validation,...
Medium
4.3
CVE-2025-9055
The VAPIX Edge storage API that allowed a privilege escalation,...
Medium
6.4
CVE-2025-8998
It was possible to upload files with a specific name...
Low
3.1
CVE-2025-8108
An ACAP configuration file has improper permissions and lacks input...
Medium
6.7
CVE-2025-7622
During an internal security assessment, a Server-Side Request Forgery (SSRF)...
Medium
5.1
Affected Vendor
Axis Communications AB
View all reports →Affected Software
AXIS OS
Vulnerable Versions:
AXIS OS 11.0.X - 11.3.x
Timeline
Official Publish:
May 8th, 2023
Last Modified:
January 29th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
No vector data available