PT-2025-14458 · Unknown+1 · Assetview Cloud+1

Published

2025-04-02

·

Updated

2025-04-02

·

CVE-2025-25060

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions AssetView versions (affected versions not specified) AssetView CLOUD versions (affected versions not specified)
Description A missing authentication for critical function vulnerability exists in the software. If exploited, a remote unauthenticated attacker may obtain and/or delete files on the server where the product is running. The issue poses a high risk for internet-facing systems.
Recommendations For AssetView, update to a version that includes a fix for the missing authentication vulnerability. For AssetView CLOUD, update to a version that includes a fix for the missing authentication vulnerability. As a temporary workaround, consider restricting access to the server where the product is running to minimize the risk of exploitation.

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-25060

Affected Products

Assetview
Assetview Cloud