VYPR

AXIS OS

by Axis

CVEs (53)

  • CVE-2025-0324CriJun 2, 2025
    risk 0.61cvss 9.4epss 0.00

    The VAPIX Device Configuration framework allowed a privilege escalation, enabling a lower-privileged user to gain administrator privileges.

  • CVE-2025-30023CriJul 11, 2025
    risk 0.59cvss 9.0epss 0.01

    The communication protocol used between client and server had a flaw that could lead to an authenticated user performing a remote code execution attack.

  • CVE-2023-21413CriOct 16, 2023
    risk 0.59cvss 9.1epss 0.01

    GoSecure on behalf of Genetec Inc. has found a flaw that allows for a remote code execution during the installation of ACAP applications on the Axis device. The application handling service in AXIS OS was vulnerable to command injection allowing an attacker to run arbitrary…

  • CVE-2025-0358HigJun 2, 2025
    risk 0.57cvss 8.8epss 0.00

    During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework that allowed a privilege escalation, enabling a lower-privileged user to gain administrator privileges.

  • CVE-2023-21407HigAug 3, 2023
    risk 0.57cvss 8.8epss 0.01

    A broken access control was found allowing for privileged escalation of the operator account to gain administrator privileges.

  • CVE-2021-31988HigOct 5, 2021
    risk 0.57cvss 8.8epss 0.01

    A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to add the Carriage Return and Line Feed (CRLF) control characters and include arbitrary SMTP headers in the generated test email.

  • CVE-2025-0359HigMar 4, 2025
    risk 0.55cvss 8.5epss 0.00

    During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the ACAP Application framework that allowed applications to access restricted D-Bus methods within the framework. Axis has released patched AXIS OS versions for the…

  • CVE-2023-21409HigAug 3, 2023
    risk 0.55cvss 8.4epss 0.01

    Due to insufficient file permissions, unprivileged users could gain access to unencrypted administrator credentials allowing the configuration of the application.

  • CVE-2025-0360HigMar 4, 2025
    risk 0.51cvss 7.8epss 0.00

    During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework that could lead to an incorrect user privilege level in the VAPIX service account D-Bus API.

  • CVE-2024-47257HigNov 26, 2024
    risk 0.49cvss 7.5epss 0.00

    Florent Thiéry has found that selected Axis devices were vulnerable to handling certain ethernet frames which could lead to the Axis device becoming unavailable in the network. Axis has released patched AXIS OS versions for the highlighted flaw for products that are still…

  • CVE-2023-5553HigNov 21, 2023
    risk 0.49cvss 7.6epss 0.00

    During internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device tampering (commonly known as Secure Boot) in AXIS OS making it vulnerable to a sophisticated attack to bypass this protection. To Axis' knowledge, there are no…

  • CVE-2021-31987HigOct 5, 2021
    risk 0.49cvss 7.5epss 0.01

    A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to bypass blocked network recipients.

  • CVE-2025-11142HigFeb 10, 2026
    risk 0.46cvss 7.1epss 0.01

    The VAPIX API mediaclip.cgi that did not have a sufficient input validation allowing for a possible remote code execution. This flaw can only be exploited after authenticating with an operator- or administrator- privileged service account.

  • CVE-2023-21418HigNov 21, 2023
    risk 0.46cvss 7.1epss 0.01

    Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API irissetup.cgi was vulnerable to path traversal attacks that allows for file deletion. This flaw can only be exploited after authenticating with an operator- or administrator-privileged service…

  • CVE-2023-21417HigNov 21, 2023
    risk 0.46cvss 7.1epss 0.01

    Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API manageoverlayimage.cgi was vulnerable to path traversal attacks that allows for file/folder deletion. This flaw can only be exploited after authenticating with an operator- or administrator-…

  • CVE-2023-21416HigNov 21, 2023
    risk 0.46cvss 7.1epss 0.01

    Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API dynamicoverlay.cgi was vulnerable to a Denial-of-Service attack allowing for an attacker to block access to the overlay configuration page in the web interface of the Axis device. This flaw can…

  • CVE-2023-21414HigOct 16, 2023
    risk 0.46cvss 7.1epss 0.00

    NCC Group has found a flaw during the annual internal penetration test ordered by Axis Communications. The protection for device tampering (commonly known as Secure Boot) contains a flaw which provides an opportunity for a sophisticated attack to bypass this protection. Axis has…

  • CVE-2026-0804MedMay 12, 2026
    risk 0.44cvss 6.7epss 0.00

    An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to potential privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications,…

  • CVE-2026-0541MedMay 12, 2026
    risk 0.44cvss 6.7epss 0.00

    ACAP applications can gain elevated privileges due to improper input validation during the installation process, potentially leading to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP…

  • CVE-2025-8108MedNov 11, 2025
    risk 0.44cvss 6.7epss 0.00

    An ACAP configuration file has improper permissions and lacks input validation, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an…

Page 1 of 3