M4328 P
Vendor:
First CVE: Oct 16, 2023 · Active for 2 years
7
Total CVEs
More Total CVEs than 83% of tracked products
3.5
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 35% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact M4328 P over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 16, 2023
2 years ago
Most Recent CVE
Nov 11, 2025
255 days ago
CVE Severity & Scoring
M4328 P7 CVEs
100%
All CVEs352,231 CVEs
45%
40%
11%
Medium
Attack Vector
Local4 (57.1%)
Network2 (28.6%)
Unknown0 (0.0%)
Physical1 (14.3%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (85.7%)
High1 (14.3%)
Unknown0 (0.0%)
User Interaction
None6 (85.7%)
Unknown0 (0.0%)
Required1 (14.3%)
Privileges Required
Low0 (0.0%)
High6 (85.7%)
None1 (14.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-6779MEDIUM An ACAP configuration file has improper permissions, which could allow command injection and potentially lead to privilege escalation. This vulnerability can only be exploited if t | Nov 11, 2025 | 6.7 | 23 | NO | NO |
CVE-2025-5718MEDIUM The ACAP Application framework could allow privilege escalation through a symlink attack. This vulnerability can only be exploited if the Axis device is configured to allow the ins | Nov 11, 2025 | 6.8 | 23 | NO | NO |
CVE-2025-4645MEDIUM An ACAP configuration file lacked sufficient input validation, which could allow for arbitrary code execution. This vulnerability can only be exploited if the Axis device is config | Nov 11, 2025 | 6.7 | 23 | NO | NO |
CVE-2025-5454MEDIUM An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to potential privilege escalation. This vulnerability can only be e | Nov 11, 2025 | 6.7 | 22 | NO | NO |
CVE-2025-5452MEDIUM A malicious ACAP application can gain access to admin-level service account credentials used by legitimate ACAP applications, leading to potential privilege escalation of the malic | Nov 11, 2025 | 6.6 | 22 | NO | NO |
CVE-2025-8108MEDIUM An ACAP configuration file has improper permissions and lacks input validation, which could potentially lead to privilege escalation. This vulnerability can only be exploited if th | Nov 11, 2025 | 6.7 | 21 | NO | NO |
CVE-2023-21414MEDIUM NCC Group has found a flaw during the annual internal penetration test ordered by Axis Communications. The protection for device tampering (commonly known as Secure Boot) contains | Oct 16, 2023 | 6.8 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (7 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (7 CVEs).
Media Mentions
Signals from CVEs in this product scope (7 CVEs).
Top CNAs Publishing CVEs For M4328 P
Top CWEs
Versions
No cataloged versions.