CVE-2025-0360

During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework that could lead to an incorrect user privilege level in the VAPIX service account D-Bus API.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:axis:axis_os:*:*:*:*:active:*:*:*
cpe:2.3:o:axis:axis_os_2024:*:*:*:*:lts:*:*:*

History

22 Jan 2026, 20:59

Type Values Removed Values Added
CPE cpe:2.3:o:axis:axis_os:*:*:*:*:active:*:*:*
cpe:2.3:o:axis:axis_os_2024:*:*:*:*:lts:*:*:*
First Time Axis axis Os
Axis axis Os 2024
Axis
References () https://www.axis.com/dam/public/b1/fe/46/cve-2025-0360pdf-en-US-466887.pdf - () https://www.axis.com/dam/public/b1/fe/46/cve-2025-0360pdf-en-US-466887.pdf - Vendor Advisory
Summary
  • (es) Durante una prueba de penetración anual realizada en nombre de Axis Communication, Truesec descubrió una falla en el marco de configuración del dispositivo VAPIX que podría generar un nivel de privilegio de usuario incorrecto en la API D-Bus de la cuenta de servicio VAPIX.

04 Mar 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-04 06:15

Updated : 2026-01-22 20:59


NVD link : CVE-2025-0360

Mitre link : CVE-2025-0360

CVE.ORG link : CVE-2025-0360


JSON object : View

Products Affected

axis

  • axis_os_2024
  • axis_os
CWE
CWE-863

Incorrect Authorization