CVE-2025-11906
BaseFortify
Publication date: 2025-10-30
Last updated on: 2025-10-30
Assigner: Progress Software Corporation
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| progress | flowmon | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-732 | The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in Progress Flowmon versions prior to 12.5.6 where certain system configuration files have incorrect file permissions. This allows a user who has access to the default Flowmon system user account used for SSH access to potentially escalate their privileges to root during service initialization.
How can this vulnerability impact me? :
The vulnerability can allow an attacker with access to the default Flowmon system user account to escalate their privileges to root, which means they could gain full control over the affected system, potentially leading to unauthorized access, data modification, or disruption of services.