VYPR

VAPIX Device Configuration

by Axis

CVEs (3)

  • CVE-2025-0358HigJun 2, 2025
    risk 0.57cvss 8.8epss 0.00

    During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework that allowed a privilege escalation, enabling a lower-privileged user to gain administrator privileges.

  • CVE-2025-0360HigMar 4, 2025
    risk 0.51cvss 7.8epss 0.00

    During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework that could lead to an incorrect user privilege level in the VAPIX service account D-Bus API.

  • CVE-2025-0361MedApr 8, 2025
    risk 0.28cvss 4.3epss 0.00

    During an annual penetration test conducted on behalf of Axis Communications, Truesec discovered a flaw in the VAPIX Device Configuration framework that allowed for unauthenticated username enumeration through the VAPIX Device Configuration SSH Management API.