{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-23T06:39:22.917","vulnerabilities":[{"cve":{"id":"CVE-2025-0361","sourceIdentifier":"product-security@axis.com","published":"2025-04-08T06:15:44.540","lastModified":"2026-01-14T14:41:02.503","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"During an annual penetration test conducted on behalf of Axis Communications, Truesec discovered a flaw in the VAPIX Device Configuration framework that allowed for unauthenticated username enumeration through the VAPIX Device Configuration SSH Management API."},{"lang":"es","value":"Durante una prueba de penetración anual realizada en nombre de Axis Communications, Truesec descubrió una falla en el marco de configuración del dispositivo VAPIX que permitía la enumeración de nombres de usuario no autenticados a través de la API de administración SSH de configuración del dispositivo VAPIX."}],"metrics":{"cvssMetricV31":[{"source":"product-security@axis.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}]},"weaknesses":[{"source":"product-security@axis.com","type":"Secondary","description":[{"lang":"en","value":"CWE-203"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:axis:axis_os:*:*:*:*:active:*:*:*","versionStartIncluding":"11.11.0","versionEndExcluding":"12.3.56","matchCriteriaId":"6570BB3D-78EA-4313-8691-A3BCF0946E29"},{"vulnerable":true,"criteria":"cpe:2.3:o:axis:axis_os_2024:*:*:*:*:lts:*:*:*","versionEndExcluding":"11.11.141","matchCriteriaId":"0ECE61EC-B83D-4222-A57A-9D8E7F42FDAA"}]}]}],"references":[{"url":"https://www.axis.com/dam/public/f4/9b/13/cve-2025-0361pdf-en-US-474511.pdf","source":"product-security@axis.com","tags":["Vendor Advisory"]}]}}]}