CVE-2025-0359

During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the ACAP Application framework that allowed applications to access restricted D-Bus methods within the framework. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:axis:axis_os:*:*:*:*:active:*:*:*
cpe:2.3:o:axis:axis_os_2024:*:*:*:*:lts:*:*:*

History

22 Jan 2026, 21:01

Type Values Removed Values Added
References () https://www.axis.com/dam/public/68/08/c5/cve-2025-0359pdf-en-US-466885.pdf - () https://www.axis.com/dam/public/68/08/c5/cve-2025-0359pdf-en-US-466885.pdf - Vendor Advisory
First Time Axis axis Os
Axis axis Os 2024
Axis
CPE cpe:2.3:o:axis:axis_os:*:*:*:*:active:*:*:*
cpe:2.3:o:axis:axis_os_2024:*:*:*:*:lts:*:*:*
Summary
  • (es) Durante una prueba de penetración anual realizada en nombre de Axis Communication, Truesec descubrió una falla en el marco de la aplicación ACAP que permitía a las aplicaciones acceder a métodos D-Bus restringidos dentro del framework. Axis ha publicado versiones parcheadas del sistema operativo AXIS para la falla destacada. Consulte el aviso de seguridad de Axis para obtener más información y soluciones.

04 Mar 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-04 06:15

Updated : 2026-01-22 21:01


NVD link : CVE-2025-0359

Mitre link : CVE-2025-0359

CVE.ORG link : CVE-2025-0359


JSON object : View

Products Affected

axis

  • axis_os_2024
  • axis_os
CWE
CWE-863

Incorrect Authorization