CVE-2021-31988
A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to add the Carriage Return and Line Feed (CRLF) control characters and include arbitrary SMTP headers in the generated test email.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.95%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to add the Carriage Return and Line Feed (CRLF) control characters and include arbitrary SMTP headers in the generated test email.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 0.95% probability · 59th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-1286, CWE-74
- Affected
- axis/axis os · axis/axis os 2016 · axis/axis os 2018 · axis/axis os 2020
- Source
- product-security@axis.com
References
- https://www.axis.com/files/tech_notes/CVE-2021-31988.pdfVendor Advisory
- https://www.axis.com/files/tech_notes/CVE-2021-31988.pdfVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.