CRITICAL🇵🇱 Wersja polska

CVE-2025-0324

CVSS 9.4v3.1pub. 2025-06-02upd. 2026-01-15

The VAPIX Device Configuration framework allowed a privilege escalation, enabling a lower-privileged user to gain administrator privileges.

🤖 AI Analysis
How it works

The VAPIX Device Configuration Framework improperly verifies the privilege level of the calling user (CWE-791 — incomplete filtering of special elements). This error allows an attacker operating as a low-privilege user to escalate to administrator level (privilege escalation) without the need to provide additional credentials. The attack is possible remotely, over the network, without any interaction from the victim.

Impact

An attacker gains full administrator privileges on an Axis device, enabling them to take complete control of device configuration, read sensitive data, and potentially modify the system.

Mitigation & patch

Apply patches available from the manufacturer according to the references — specific versions fixing the vulnerability are provided in Axis's official security bulletin.

Who is affected

Axis OS 2024 and Axis OS — specific versions indicated in the manufacturer's references (https://www.axis.com/dam/public/04/f3/1c/cve-2025-0324pdf-en-US-483807.pdf)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
  • Axis Os

    OS
    Axis
    12.0.0 – 12.3.33 (excl.)
  • Axis Os 2024

    OS
    Axis
    11.8.0 – 11.11.140 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
LPE
CWE
References

Related vulnerabilities

CVE-2023-21413CRITICAL9.1PL ✓same product

Command Injection w AXIS OS podczas instalacji aplikacji ACAP — RCE

CVE-2025-11142HIGH7.1same product

The VAPIX API mediaclip.cgi that did not have a sufficient input validation allowing for a possible remote cod...

CVE-2025-0358HIGH8.8same product

During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the ...

CVE-2025-0360HIGH7.8same product

During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the ...

CVE-2025-0359HIGH8.5same product

During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the ...