ZeroHour

CVE-2025-3892

CVSS 3.1
6.7 medium
EPSS
<1%p4
Published
()
Modified
Description

ACAP applications can be executed with elevated privileges, potentially leading to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.

Vendors
axis
Products
axis os
Weakness
CWE-250
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.