Severity
5.5MEDIUM
EPSS
0.1%
top 70.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 4

Description

During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the ACAP Application framework that allowed applications to access restricted D-Bus methods within the framework. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:LExploitability: 2.5 | Impact: 5.3

Affected Packages3 packages

CVEListV5axis_communications_ab/axis_os11.11.011.11.135+1
NVDaxis/axis_os11.11.012.2.52
NVDaxis/axis_os_2024< 11.11.135

🔴Vulnerability Details

2
CVEList
CVE-2025-0359: During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the ACAP Application framework that allowed2025-03-04
GHSA
GHSA-xj5q-cgqf-crw9: During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the ACAP Application framework that allowed2025-03-04

📋Vendor Advisories

1
Microsoft
Heap-based Buffer Overflow in vim/vim2022-01-11