CVE-2025-0360

During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework that could lead to an incorrect user privilege level in the VAPIX service account D-Bus API.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:axis:axis_os:*:*:*:*:active:*:*:*
cpe:2.3:o:axis:axis_os_2024:*:*:*:*:lts:*:*:*

History

No history.

Information

Published : 2025-03-04 06:15

Updated : 2026-01-22 20:59


NVD link : CVE-2025-0360

Mitre link : CVE-2025-0360

CVE.ORG link : CVE-2025-0360


JSON object : View

Products Affected

axis

  • axis_os
  • axis_os_2024
CWE
CWE-863

Incorrect Authorization