ZeroHour

CVE-2025-0361

CVSS 3.1
5.3 medium
EPSS
<1%p25
Published
()
Modified
Description

During an annual penetration test conducted on behalf of Axis Communications, Truesec discovered a flaw in the VAPIX Device Configuration framework that allowed for unauthenticated username enumeration through the VAPIX Device Configuration SSH Management API.

Vendors
axis
Products
axis os, axis os 2024
Weakness
CWE-203
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.