Sensitive Data Exposure in Axis Communications Devices and Solutions
CVE-2025-6571
6MEDIUM
What is CVE-2025-6571?
A vulnerability has been identified in various products by Axis Communications where a third-party component inadvertently exposes sensitive passwords through process arguments. This situation enables low-privileged users to potentially exploit the system and gain unauthorized access to sensitive credentials, leading to broader security implications.
Affected Version(s)
AXIS OS 12.0.0 < 12.6.66
AXIS OS 11.11.0 < 11.11.169
References
CVSS V3.1
Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
URCQ
