CVE-2025-22956
BaseFortify
Publication date: 2025-09-08
Last updated on: 2025-09-09
Assigner: MITRE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| uib | opsi | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-200 | The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in OPSI versions before 4.3 allows any client to retrieve any ProductPropertyState, including those belonging to other clients. This means that sensitive information, such as secrets or passwords intended only for specific clients, can be accessed by unauthorized clients. For example, a domain join account password for the windomain package could be exposed.
How can this vulnerability impact me? :
The vulnerability can lead to privilege escalation by exposing sensitive information that should be restricted. Unauthorized clients could gain access to secrets like domain join account passwords, potentially allowing them to perform unauthorized actions or access restricted systems.