PT-2025-31156 · Appliance · Appliance

Jim Becher

·

Published

2025-07-28

·

Updated

2025-10-09

·

CVE-2025-54765

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions (affected versions not specified)
Description An API endpoint intended for web application administrators is accessible to lower-level read-only users. This allows unauthorized access to appliance configuration import functionality, potentially enabling an attacker to gain administrative privileges. The vulnerable API endpoint allows control over the appliance configuration.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

LPE

Weakness Enumeration

Related Identifiers

CVE-2025-54765

Affected Products

Appliance