Impact
An Axis Communications ACAP configuration file accepts unvalidated input, allowing an attacker who persuades a user to install a malicious ACAP application to obtain elevated privileges on the device. The flaw results from missing input validation and can increase the attacker's control over the system. The primary consequence is the potential to gain higher authorization levels than the user originally had, without exploiting a separate vulnerability. The weakness is identified as CWE-1287.
Affected Systems
Axis Communications devices running AXIS OS are affected when they are configured to permit the installation of unsigned ACAP applications. The vulnerability applies only to devices that allow such installations and to users who install a malicious ACAP package. No specific firmware or software version numbers are provided, so administrators should review all AXIS OS deployments with unsigned ACAP support.
Risk and Exploitability
The CVSS score of 5.7 indicates a moderate severity. The EPSS score is currently not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited evidence of exploitation so far. Attackers need a user-initiated installation of a malicious ACAP and an Axis device with unsigned ACAP support; no network‑bypass or remote code execution is possible without that user action. Given the dependency on user behavior and configuration settings, the likelihood of exploitation is moderate, but the potential privilege escalation remains a concern if the device is exposed to untrusted users or applications.
OpenCVE Enrichment