PT-2025-48685 · Gams · Gams

Published

2025-12-02

·

Updated

2026-02-03

·

CVE-2025-41086

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions GAMS (affected versions not specified)
Description A flaw exists in the access control system of the GAMS licensing system that permits the creation of an unlimited number of valid licenses, circumventing usage limitations. The system employs an insecure checksum algorithm. An attacker, by understanding this algorithm and the license line format, can recalculate the checksum and forge a valid license. This grants the attacker full privileges without requiring credentials or access to the source code, enabling unrestricted access to GAMS’s mathematical models and commercial solvers.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

IDOR

Weakness Enumeration

Related Identifiers

CVE-2025-41086

Affected Products

Gams