CVE-2025-25060
CVSS 3.0 Score 8.2 of 10 (high)
Attack Complexity low
Confidentiality high
Integrity low
Availability none
Scope unchanged
Privileges Required none
Details
Published Apr 2, 2025
CWE ID 306
Summary
CVE-2025-25060 is a critical vulnerability affecting AssetView and AssetView CLOUD. The issue involves a missing authentication mechanism for a crucial function, allowing unauthenticated attackers to gain access to files on the affected server. They can potentially obtain sensitive data or delete files, causing significant damage. The vulnerability poses a serious security risk and requires immediate attention from users to apply available patches.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.