PT-2025-12376 · Esri · Arcgis Enterprise

Published

2025-03-20

·

Updated

2025-12-10

·

CVE-2025-2538

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Esri ArcGIS Enterprise versions 10.9.1 through 11.4
Description A specific type of ArcGIS Enterprise deployment is vulnerable to a password recovery exploitation vulnerability in Portal, which could allow an attacker to reset the password on the built-in admin account. This issue could permit attackers to hijack built-in administrative accounts through a password reset flaw. The vulnerability is considered critical and could risk data breaches.
Recommendations For versions 10.9.1 through 11.4, consider disabling the password recovery feature in Portal until a patch is available. Restrict access to the administrative account to minimize the risk of exploitation. As a temporary workaround, limit the use of the built-in admin account until the issue is resolved.

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

BDU:2025-14627
CVE-2025-2538

Affected Products

Arcgis Enterprise