3.1

CVE-2025-8998

It was possible to upload files with a specific name to a temporary directory, which may result in process crashes and impact usability. This flaw can only be exploited after authenticating with an operator- or administrator-privileged service account.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerAxis Communications AB
Produkt AXIS OS
Default Statusunaffected
Version 6.50.0
Version < 6.50.5.22
Status affected
Version 7.0.0
Version < 8.40.90
Status affected
Version 9.0.0
Version < 9.80.124
Status affected
Version 10.0.0
Version < 10.12.306
Status affected
Version 11.0.0
Version < 11.11.178
Status affected
Version 12.0.0
Version < 12.7.27
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.04% 0.124
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
product-security@axis.com 3.1 1.6 1.4
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
CWE-73 External Control of File Name or Path

The product allows user input to control or influence paths or file names that are used in filesystem operations.