Axis VAPIX Device Configuration Privilege Escalation Vulnerability

Vulnerability

A privilege escalation vulnerability has been identified in the VAPIX Device Configuration framework of Axis products running AXIS OS versions 11.8 through 12.2. This vulnerability allows a lower-privileged user to gain administrator privileges.

Impact

Exploitation of this vulnerability allows for unauthorized privilege escalation, enabling lower-privileged users to obtain administrator rights.

Remediation

Axis has released patches for this vulnerability in AXIS OS Active Track 12.3.33 and LTS 2024 11.11.140. For devices not included in these tracks but still under support, patches will be released according to the planned maintenance and release schedule. Users are advised to update their Axis device software to the latest version available.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
6.8
impact
5.0
exploitability
4.9
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.