Impact
The Device Configuration Framework of Axis Communications AB AXIS OS has a flaw that allows an authenticated user with viewer privileges to bypass normal authorization checks. An attacker with such an account could access configuration functions that normally require higher authority, potentially enabling unauthorized configuration changes, data exposure or device compromise.
Affected Systems
Axis Communications AB AXIS OS devices are affected. The advisory does not list specific firmware or software version numbers, so all installations of the mentioned framework should be considered vulnerable.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity. No EPSS value is available and the vulnerability is not listed in CISA KEV, suggesting no known widespread exploitation. The exploit requires a viewer‑privileged service account, which implies an internal attack or credential compromise. Based on the description, it is inferred that the attack vector requires authenticated access, likely from within the network or from a compromised account.
OpenCVE Enrichment