CVE-2025-69270
Information Exposure in Broadcom DX NetOps Spectrum Enables Session Hijacking
Publication date: 2026-01-12
Last updated on: 2026-01-12
Assigner: CA Technologies - A Broadcom Company
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| broadcom | dx_netops_spectrum | to 24.3.8 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-598 | The web application uses the HTTP GET method to process a request and includes sensitive information in the query string of that request. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an Information Exposure Through Query Strings in GET Request issue in Broadcom DX NetOps Spectrum on Windows and Linux. It allows an attacker to hijack a user session by accessing sensitive information exposed in the query strings of GET requests.
How can this vulnerability impact me? :
The vulnerability can lead to session hijacking, where an attacker can gain unauthorized access to a user's session. This can result in unauthorized actions being performed on behalf of the user, potentially compromising system security and user data.