CVE-2025-0360 Details
Description
During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework that could lead to an incorrect user privilege level in the VAPIX service account D-Bus API.
A vulnerability has been identified in the VAPIX Device Configuration framework of Axis products running AXIS OS 11.11 through AXIS OS 12.1. This flaw can lead to incorrect user privilege levels in the VAPIX service account D-Bus API. The vulnerability was discovered during a penetration test by Truesec, and has been assigned a CVSSv3.1 score of 7.8, indicating high severity.
Axis has released patches for this vulnerability in the following versions: Active Track 12.2.41 and LTS 2024 11.11.135. For devices not included in these tracks but still under support, patches will be provided according to the planned maintenance and release schedule. Users are advised to update their Axis device software to the latest version available.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 4, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.axis.com/dam/public/b1/fe/46/cve-2025-0360pdf-en-US-466887.pdf | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| axis axis os | >= 11.11.0, < 12.2.41 |
CPE
Remediation
| |
| axis axis os 2024 | < 11.11.135 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 22, 2026 | Initial Analysis | [email protected] |
| Mar 4, 2025 | New CVE Received | [email protected] |