CVE-2025-69270
Unknown
Unknown - Not Provided
Information Exposure in Broadcom DX NetOps Spectrum Enables Session Hijacking
Publication date: 2026-01-12
Last updated on: 2026-01-12
Assigner: CA Technologies - A Broadcom Company
Description
Description
Information Exposure Through Query Strings in GET Request vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Session Hijacking.This issue affects DX NetOps Spectrum: 24.3.8 and earlier.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| broadcom | dx_netops_spectrum | to 24.3.8 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-598 | The web application uses the HTTP GET method to process a request and includes sensitive information in the query string of that request. |