PT-2025-29200 · Apache · Apache Http Server

Noam Moshe

·

Published

2025-07-11

·

Updated

2025-08-08

·

CVE-2025-30023

CVSS v3.1
9.0
VectorAV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Name of the Vulnerable Software and Affected Versions:

Axis Video Management Software (affected versions not specified)

Description:

The communication protocol used between the client and server has a flaw that could allow an authenticated user to perform a remote code execution attack. The issue involves improper serialized data handling between the client and server, enabling attackers to execute code without user interaction, which is suitable for lateral movement within a network.

Recommendations:

At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2025-30023

Affected Products

Apache Http Server