{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-01T03:03:24.160","vulnerabilities":[{"cve":{"id":"CVE-2025-9055","sourceIdentifier":"product-security@axis.com","published":"2025-11-11T08:15:35.057","lastModified":"2026-06-17T10:08:14.113","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The VAPIX Edge storage API that allowed a privilege escalation, enabling a VAPIX administrator-privileged user to gain Linux Root privileges. This flaw can only be exploited after authenticating with an administrator-privileged service account."}],"affected":[{"source":"product-security@axis.com","affectedData":[{"vendor":"Axis Communications AB","product":"AXIS OS","defaultStatus":"unaffected","versions":[{"version":"12.0.0","lessThan":"12.7.31","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"product-security@axis.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":0.5,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-11-12T04:57:49.189814Z","id":"CVE-2025-9055","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"product-security@axis.com","type":"Secondary","description":[{"lang":"en","value":"CWE-250"}]}],"references":[{"url":"https://www.axis.com/dam/public/23/a3/00/cve-2025-9055pdf-en-US-504219.pdf","source":"product-security@axis.com"}]}}]}