CVE-2025-0324: Critical severity Axis AXIS OS vulnerability
Published Jun 2, 2025
·Updated
The VAPIX Device Configuration framework allowed a privilege escalation, enabling a lower-privileged user to gain administrator privileges.
Affected Software
2 affected components
Axis AXIS OS>=12.0.0<12.3.33
Axis Axis Os 2024>=11.8.0<11.11.140
Event History
Jun 2, 2025
CVE Published
via MITRE·07:32 AM
Data Sourced
via MITRE·07:32 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-0324?
CVE-2025-0324 has been assessed as a high severity vulnerability due to the potential for privilege escalation.
2
How do I fix CVE-2025-0324?
To fix CVE-2025-0324, ensure that your Axis OS is updated to the latest version beyond 12.3.33 for Axis OS or beyond 11.11.140 for Axis OS 2024.
3
What is the impact of CVE-2025-0324?
The impact of CVE-2025-0324 allows lower-privileged users to gain administrator privileges, jeopardizing device security.
4
Which versions are affected by CVE-2025-0324?
CVE-2025-0324 affects Axis OS versions between 12.0.0 and 12.3.33, and Axis OS 2024 versions between 11.8.0 and 11.11.140.
5
Who is affected by CVE-2025-0324?
Organizations using vulnerable versions of Axis OS and Axis OS 2024 are at risk from CVE-2025-0324.