CVE-2025-54943
BaseFortify
Publication date: 2025-08-30
Last updated on: 2025-09-25
Assigner: ZUSO Advanced Research Team (ZUSO ART)
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| sun.net | ehrd_ctms | to 10.11 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-862 | The product does not perform an authorization check when an actor attempts to access a resource or perform an action. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a missing authorization flaw in the SUNNET Corporate Training Management System versions before 10.11. It allows remote attackers to deploy applications without proper access control checks, meaning unauthorized users can perform actions they should not be allowed to.
How can this vulnerability impact me? :
The vulnerability can lead to unauthorized application deployment by remote attackers, potentially compromising the integrity and security of the system. This could result in malicious software being installed, unauthorized changes, or other security breaches.