CVE-2025-0360

D

uring an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework that could lead to an incorrect user privilege level in the VAPIX service account D-Bus API.

Configurations

Configuration 1 (hide)

OR cpe:2.3:o:axis:axis_os:*:*:*:*:active:*:*:*
cpe:2.3:o:axis:axis_os_2024:*:*:*:*:lts:*:*:*

History

22 Jan 2026, 20:59

Type Values Removed Values Added
References () https://www.axis.com/dam/public/b1/fe/46/cve-2025-0360pdf-en-US-466887.pdf - () https://www.axis.com/dam/public/b1/fe/46/cve-2025-0360pdf-en-US-466887.pdf - Vendor Advisory
CPE cpe:2.3:o:axis:axis_os:*:*:*:*:active:*:*:*
cpe:2.3:o:axis:axis_os_2024:*:*:*:*:lts:*:*:*
Summary
  • (es) Durante una prueba de penetración anual realizada en nombre de Axis Communication, Truesec descubrió una falla en el marco de configuración del dispositivo VAPIX que podría generar un nivel de privilegio de usuario incorrecto en la API D-Bus de la cuenta de servicio VAPIX.
First Time Axis axis Os
Axis
Axis axis Os 2024

04 Mar 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-04 06:15

Updated : 2026-01-22 20:59


NVD link : CVE-2025-0360

Mitre link : CVE-2025-0360

CVE.ORG link : CVE-2025-0360


JSON object : View

Products Affected
CWE
CWE-863

Incorrect Authorization