{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-02T10:47:38.472","vulnerabilities":[{"cve":{"id":"CVE-2025-0359","sourceIdentifier":"product-security@axis.com","published":"2025-03-04T06:15:30.023","lastModified":"2026-06-17T08:26:20.757","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the ACAP Application framework that allowed applications to access restricted D-Bus methods within the framework. \nAxis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution."},{"lang":"es","value":"Durante una prueba de penetración anual realizada en nombre de Axis Communication, Truesec descubrió una falla en el marco de la aplicación ACAP que permitía a las aplicaciones acceder a métodos D-Bus restringidos dentro del framework. Axis ha publicado versiones parcheadas del sistema operativo AXIS para la falla destacada. Consulte el aviso de seguridad de Axis para obtener más información y soluciones."}],"affected":[{"source":"product-security@axis.com","affectedData":[{"vendor":"Axis Communications AB","product":"AXIS OS","defaultStatus":"unaffected","versions":[{"version":"11.11.0","lessThan":"11.11.135","versionType":"semver","status":"affected"},{"version":"12.0.0","lessThan":"12.2.52","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"product-security@axis.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L","baseScore":8.5,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":2.5,"impactScore":5.3},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-03-04T15:18:21.373964Z","id":"CVE-2025-0359","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"product-security@axis.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:axis:axis_os:*:*:*:*:active:*:*:*","versionStartIncluding":"11.11.0","versionEndExcluding":"12.2.52","matchCriteriaId":"4CE29EC9-EB6F-44EF-ACBB-A484B7D8E7E6"},{"vulnerable":true,"criteria":"cpe:2.3:o:axis:axis_os_2024:*:*:*:*:lts:*:*:*","versionEndExcluding":"11.11.135","matchCriteriaId":"A3ACD321-ABF7-46AE-A389-E8FD76EF0C51"}]}]}],"references":[{"url":"https://www.axis.com/dam/public/68/08/c5/cve-2025-0359pdf-en-US-466885.pdf","source":"product-security@axis.com","tags":["Vendor Advisory"]}]}}]}