CVE-2025-10609
BaseFortify
Publication date: 2025-10-03
Last updated on: 2025-10-06
Assigner: Computer Emergency Response Team of the Republic of Turkey
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| logo_software_inc | tigerwings_erp | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-798 | The product contains hard-coded credentials, such as a password or cryptographic key. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability involves the use of hard-coded credentials in Logo Software Inc.'s TigerWings ERP software. It allows an attacker to read sensitive constants within the executable, potentially exposing important information embedded in the software. This issue affects versions of TigerWings ERP before 3.03.00.
How can this vulnerability impact me? :
The vulnerability can impact you by allowing an attacker with limited privileges to read sensitive information embedded in the software, which could lead to further exploitation or unauthorized actions. The CVSS score indicates a high impact on integrity and a low impact on availability, meaning the attacker could alter data or behavior but not necessarily disrupt service.