CVE-2021-31988
 
Severity Score
8.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to add the Carriage Return and Line Feed (CRLF) control characters and include arbitrary SMTP headers in the generated test email.
Un parámetro controlado por el usuario relacionado con la funcionalidad de prueba de SMTP no es comprobado correctamente, haciendo posible añadir los caracteres de control Carriage Return and Line Feed (CRLF) e incluir encabezados SMTP arbitrarios en el correo electrónico de prueba generado
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2021-04-30 CVE Reserved
- 2021-10-05 CVE Published
- 2024-06-20 EPSS Updated
- 2024-11-08 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
- CWE-1286: Improper Validation of Syntactic Correctness of Input
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.axis.com/files/tech_notes/CVE-2021-31988.pdf | 2022-07-12 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Axis Search vendor "Axis" | Axis Os Search vendor "Axis" for product "Axis Os" | < 10.7 Search vendor "Axis" for product "Axis Os" and version " < 10.7" | active |
Affected
| ||||||
Axis Search vendor "Axis" | Axis Os 2016 Search vendor "Axis" for product "Axis Os 2016" | < 6.50.5.5 Search vendor "Axis" for product "Axis Os 2016" and version " < 6.50.5.5" | lts |
Affected
| ||||||
Axis Search vendor "Axis" | Axis Os 2018 Search vendor "Axis" for product "Axis Os 2018" | < 8.40.4.3 Search vendor "Axis" for product "Axis Os 2018" and version " < 8.40.4.3" | lts |
Affected
| ||||||
Axis Search vendor "Axis" | Axis Os 2020 Search vendor "Axis" for product "Axis Os 2020" | < 9.80.3.5 Search vendor "Axis" for product "Axis Os 2020" and version " < 9.80.3.5" | lts |
Affected
|