Privilege Escalation in VAPIX Device Configuration by Axis Communications
CVE-2025-0324
9.4CRITICAL
What is CVE-2025-0324?
The VAPIX Device Configuration framework has a vulnerability that allows lower-privileged users to elevate their privileges to that of an administrator. This flaw poses a significant risk, as it can be exploited by unauthorized users to gain control over sensitive functions and settings, potentially compromising the security of devices utilizing the VAPIX framework. Organizations should implement immediate measures to secure their systems from this vulnerability.
Affected Version(s)
AXIS OS 11.8.0 < 11.11.140
AXIS OS 12.0.0 < 12.3.33