216.73.217.22

CVE-2025-22375

· Published 10/04/2025 11:15 · Modified 10/04/2025 11:15

Labels: CVE-2025-22375 2025-04-10CVE-2025-22375CWE-287[email protected]

Essential information

Published
10/04/2025 11:15
Modified
10/04/2025 11:15
Author
Creator
CVSS
9.3 CRITICAL (v3) 9.3 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

An authentication bypass vulnerability was found in Videx's CyberAudit-Web. Through the exploitation of a logic flaw, an attacker could create a valid session without any credentials. This vulnerability has been patched in versions later than 9.5 and a patch has been made available to all instances of CyberAudit-Web, including the versions that are End of Maintenance (EOM). Anyone that requires support with the resolution of this issue can contact [email protected] for assistance.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
videx / cyberaudit-web cpe:2.3:a:videx:cyberaudit-web:>9.5:*:*:*:*:*:*:*

References