3.1
CVE-2025-8998
- EPSS 0.04%
- Veröffentlicht 11.11.2025 07:28:40
- Zuletzt bearbeitet 15.04.2026 00:35:42
- Quelle product-security@axis.com
- CVE-Watchlists
- Unerledigt
It was possible to upload files with a specific name to a temporary directory, which may result in process crashes and impact usability. This flaw can only be exploited after authenticating with an operator- or administrator-privileged service account.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerAxis Communications AB
≫
Produkt
AXIS OS
Default Statusunaffected
Version
6.50.0
Version <
6.50.5.22
Status
affected
Version
7.0.0
Version <
8.40.90
Status
affected
Version
9.0.0
Version <
9.80.124
Status
affected
Version
10.0.0
Version <
10.12.306
Status
affected
Version
11.0.0
Version <
11.11.178
Status
affected
Version
12.0.0
Version <
12.7.27
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.04% | 0.124 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| product-security@axis.com | 3.1 | 1.6 | 1.4 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
|
CWE-73 External Control of File Name or Path
The product allows user input to control or influence paths or file names that are used in filesystem operations.