216.73.216.233

CVE-2025-3838

· Published 21/04/2025 10:15 · Modified 21/04/2025 14:23

Labels: CVE-2025-3838 2025-04-21CVE-2025-3838CWE-327bd8dbf88-98d9-42c6-be08-cf8e48a32093

Essential information

Published
21/04/2025 10:15
Modified
21/04/2025 14:23
Author
Creator
CVSS
6.1 MEDIUM (v3) 6.1 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

An Improper Authorization vulnerability was identified in the EOL OVA based connect component which is deployed for installation purposes in the customer internal network. Under certain conditions, this could allow a bad actor to gain unauthorized access to the local db containing weakly hashed credentials of the installer. This EOL component was deprecated in September 2023 with end of support extended till January 2024.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
bd8dbf88-98d9-42c6-be08-cf8e48a32093
NVD
View on NVD

Affected products (CPE)

ProductCPE
unknown / ova based connect component cpe:2.3:a:unknown:ova_based_connect_component:*:*:*:*:*:*:*:*

References