AXIS OS 11.0.X - 11.3.x use a static RSA key in legacy LUA-components to protect Axis-specific source code. The static RSA key is not used in any other secure communication nor can it be used to compromise the device or any customer data.
The product uses a hard-coded, unchangeable cryptographic key.
The product does not encrypt sensitive or critical information before storage or transmission.
Link | Tags |
---|---|
https://www.axis.com/dam/public/07/0a/20/cve-2023-21404-en-US-398426.pdf | vendor advisory |