CVE-2025-0361Observable Discrepancy in Communications AB Axis OS

Severity
5.3MEDIUMNVD
CNA4.3
EPSS
0.2%
top 57.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 8

Description

During an annual penetration test conducted on behalf of Axis Communications, Truesec discovered a flaw in the VAPIX Device Configuration framework that allowed for unauthenticated username enumeration through the VAPIX Device Configuration SSH Management API.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages3 packages

CVEListV5axis_communications_ab/axis_os11.11.011.11.141+1
NVDaxis/axis_os11.11.012.3.56
NVDaxis/axis_os_2024< 11.11.141

🔴Vulnerability Details

2
CVEList
CVE-2025-0361: During an annual penetration test conducted on behalf of Axis Communications, Truesec discovered a flaw in the VAPIX Device Configuration framework th2025-04-08
GHSA
GHSA-294x-x7jx-8864: During an annual penetration test conducted on behalf of Axis Communications, Truesec discovered a flaw in the VAPIX Device Configuration framework th2025-04-08

📋Vendor Advisories

1
Microsoft
Heap-based Buffer Overflow in vim/vim2022-01-11
CVE-2025-0361 — Observable Discrepancy | cvebase