PT-2025-40103 · Imsoft · Ca Unified Infrastructure Management+1

Published

2025-10-01

·

Updated

2025-10-01

·

CVE-2025-10847

CVSS v4.0

8.4

High

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:H/VA:H/SC:L/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:D/RE:L/U:Amber
Name of the Vulnerable Software and Affected Versions DX Unified Infrastructure Management (Nimsoft/UIM) versions prior to 8.63
Description The software contains an improper Access Control List (ACL) handling issue within the robot (controller) component. A remote attacker may be able to execute commands, read data from, or write data to the targeted system.
Recommendations Update to version 8.63 or later.

Fix

RCE

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2025-10847

Affected Products

Ca Unified Infrastructure Management
Nimsoft Uim