← Back

CVE-2021-31988

nvd nist
Published: Oct 5, 2021Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to add the Carriage Return and Line Feed (CRLF) control characters and include arbitrary SMTP headers in the generated test email.

Affected (4)

4 products
Axis Os
Axis Os 2016
Axis Os 2018
Axis Os 2020
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Before 10.7
Before 6.50.5.5
Before 8.40.4.3
Before 9.80.3.5

References (2)

Source: product-security@axis.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.