PT-2025-23478 · Axis Communications · Vapix Device Configuration Framework

CVE-2025-0358

·

Publicado

2025-06-02

·

Atualizado

2025-06-07

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Axis Communication VAPIX Device Configuration framework (affected versions not specified)
Description A flaw in the VAPIX Device Configuration framework was discovered, allowing a lower-privileged user to gain administrator privileges through privilege escalation. This issue was found during an annual penetration test conducted by Truesec on behalf of Axis Communication.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-06379
CVE-2025-0358

Produtos afetados

Vapix Device Configuration Framework