SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-31988

A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to add the Carriage Return and Line Feed (CRLF) control characters and include arbitrary SMTP headers in the generated test email.

HIGH 8.8EPSS 0.95%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.95%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to add the Carriage Return and Line Feed (CRLF) control characters and include arbitrary SMTP headers in the generated test email.

CVSS 3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
0.95% probability · 59th percentile
CISA KEV
Not listed
Weakness
CWE-1286, CWE-74
Affected
axis/axis os · axis/axis os 2016 · axis/axis os 2018 · axis/axis os 2020
Source
product-security@axis.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.