During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework that could lead to an incorrect user privilege level in the VAPIX service account D-Bus API.
History

Thu, 22 Jan 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Axis
Axis axis Os
Axis axis Os 2024
CPEs cpe:2.3:o:axis:axis_os:*:*:*:*:active:*:*:*
cpe:2.3:o:axis:axis_os_2024:*:*:*:*:lts:*:*:*
Vendors & Products Axis
Axis axis Os
Axis axis Os 2024

Tue, 11 Mar 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 04 Mar 2025 05:30:00 +0000

Type Values Removed Values Added
Description During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework that could lead to an incorrect user privilege level in the VAPIX service account D-Bus API.
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Axis

Published:

Updated: 2025-03-26T12:09:06.856Z

Reserved: 2025-01-09T08:02:46.361Z

Link: CVE-2025-0360

cve-icon Vulnrichment

Updated: 2025-03-04T15:24:38.164Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-04T06:15:30.180

Modified: 2026-01-22T20:59:43.883

Link: CVE-2025-0360

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.