CVE-2025-8284
BaseFortify
Publication date: 2025-08-08
Last updated on: 2025-08-08
Assigner: ICS-CERT
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-306 | The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists because the Packet Power Monitoring and Control Web Interface does not enforce authentication by default. This means that unauthorized users can access the interface without needing to log in, allowing them to view and manipulate monitoring and control functions.
How can this vulnerability impact me? :
The vulnerability can have a severe impact as unauthorized users could gain full access to monitoring and control functions. This could lead to manipulation of system operations, potentially causing disruptions, data loss, or unauthorized control over the monitored environment.