PT-2025-52626 · Ragic · Ragic Enterprise Cloud Database

Sideman

·

Published

2025-12-22

·

Updated

2025-12-27

·

CVE-2025-15016

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ragic Enterprise Cloud Database (affected versions not specified)
Description The Ragic Enterprise Cloud Database contains a hard-coded cryptographic key issue. This allows unauthenticated remote attackers to exploit the fixed key to generate verification information and log into the system as any user. The issue enables attackers to bypass authentication completely and impersonate any user.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2025-15016

Affected Products

Ragic Enterprise Cloud Database