During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework that could lead to an incorrect user privilege level in the VAPIX service account D-Bus API.
History

Tue, 11 Mar 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 04 Mar 2025 05:30:00 +0000

Type Values Removed Values Added
Description During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework that could lead to an incorrect user privilege level in the VAPIX service account D-Bus API.
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Axis

Published: 2025-03-04T05:24:00.720Z

Updated: 2025-03-26T12:09:06.856Z

Reserved: 2025-01-09T08:02:46.361Z

Link: CVE-2025-0360

cve-icon Vulnrichment

Updated: 2025-03-04T15:24:38.164Z

cve-icon NVD

Status : Received

Published: 2025-03-04T06:15:30.180

Modified: 2025-03-04T06:15:30.180

Link: CVE-2025-0360

cve-icon Redhat

No data.