Axis AXIS OS
cpe:2.3:o:axis:axis_os:*:*:*:*:*:*:*
- >= 11.11, <= 12.1
A vulnerability has been identified in the VAPIX Device Configuration framework of Axis products running AXIS OS 11.11 through AXIS OS 12.1. This flaw can lead to incorrect user privilege levels in the VAPIX service account D-Bus API. The vulnerability was discovered during a penetration test by Truesec, and has been assigned a CVSSv3.1 score of 7.8, indicating high severity.
Exploitation of this vulnerability could result in incorrect authorization, allowing users to gain elevated privileges in the VAPIX service account D-Bus API.
Axis has released patches for this vulnerability in the following versions: Active Track 12.2.41 and LTS 2024 11.11.135. For devices not included in these tracks but still under support, patches will be provided according to the planned maintenance and release schedule. Users are advised to update their Axis device software to the latest version available.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.