Missing authentication for critical function vulnerability exists in AssetView and AssetView CLOUD. If exploited, the files on the server where the product is running may be obtained and/or deleted by a remote unauthenticated attacker.
History

Wed, 02 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Apr 2025 03:30:00 +0000

Type Values Removed Values Added
Description Missing authentication for critical function vulnerability exists in AssetView and AssetView CLOUD. If exploited, the files on the server where the product is running may be obtained and/or deleted by a remote unauthenticated attacker.
Weaknesses CWE-306
References
Metrics cvssV3_0

{'score': 8.2, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2025-04-02T16:04:49.028Z

Reserved: 2025-03-07T06:04:12.829Z

Link: CVE-2025-25060

cve-icon Vulnrichment

Updated: 2025-04-02T16:04:43.485Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-02T04:15:34.993

Modified: 2025-04-02T14:58:07.527

Link: CVE-2025-25060

cve-icon Redhat

No data.