Description
During an annual penetration test conducted on behalf of Axis Communications, Truesec discovered a flaw in the VAPIX Device Configuration framework that allowed for unauthenticated username enumeration through the VAPIX Device Configuration SSH Management API.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-10068 | During an annual penetration test conducted on behalf of Axis Communications, Truesec discovered a flaw in the VAPIX Device Configuration framework that allowed for unauthenticated username enumeration through the VAPIX Device Configuration SSH Management API. |
References
History
Wed, 14 Jan 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Axis
Axis axis Os Axis axis Os 2024 |
|
| CPEs | cpe:2.3:o:axis:axis_os:*:*:*:*:active:*:*:* cpe:2.3:o:axis:axis_os_2024:*:*:*:*:lts:*:*:* |
|
| Vendors & Products |
Axis
Axis axis Os Axis axis Os 2024 |
Tue, 08 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Apr 2025 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | During an annual penetration test conducted on behalf of Axis Communications, Truesec discovered a flaw in the VAPIX Device Configuration framework that allowed for unauthenticated username enumeration through the VAPIX Device Configuration SSH Management API. | |
| Weaknesses | CWE-203 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Axis
Published:
Updated: 2025-04-08T14:50:47.286Z
Reserved: 2025-01-09T08:02:54.458Z
Link: CVE-2025-0361
Updated: 2025-04-08T13:21:51.588Z
Status : Analyzed
Published: 2025-04-08T06:15:44.540
Modified: 2026-01-14T14:41:02.503
Link: CVE-2025-0361
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD