Cyber Posture

CVE-2025-0674

Critical

Published: 07 February 2025

Published
07 February 2025
Modified
15 April 2026
KEV Added
Patch
CVSS Score 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.1575 94.7th percentile
Risk Priority 29 60% EPSS · 20% KEV · 20% CVSS

Description

Multiple Elber products are affected by an authentication bypass vulnerability which allows unauthorized access to the password management functionality. Attackers can exploit this issue by manipulating the endpoint to overwrite any user's password within the system. This grants them unauthorized administrative access to protected areas of the application, compromising the device's system security.

Security Summary

CVE-2025-0674 is an authentication bypass vulnerability (CWE-288) affecting multiple Elber products. The flaw enables unauthorized access to the password management functionality through endpoint manipulation, allowing attackers to overwrite any user's password within the system. Published on 2025-02-07, it carries a CVSS v3.1 base score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), indicating critical severity with high impacts on confidentiality, integrity, and availability.

Unauthenticated attackers can exploit this vulnerability remotely over the network with low complexity and no user interaction required. By targeting the affected endpoint, they can reset passwords for any user, thereby gaining unauthorized administrative access to protected areas of the application and fully compromising the device's system security.

The CISA ICS Advisory ICSA-25-035-03 provides further details on this vulnerability, including mitigation recommendations, available at https://www.cisa.gov/news-events/ics-advisories/icsa-25-035-03.

Details

CWE(s)
CWE-288

References