← All CVEs

CVE-2025-2500

critical · 9.1

A vulnerability exists in the SOAP Web services of the Asset Suite versions listed below. If successfully exploited, an attacker could gain unauthorized access to the product and the time window of a possible password attack could be expanded.

9.1
CVSS
0.4%
EPSS (exploit prob.)
32nd
EPSS percentile
2025-05-30
Published

CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Weaknesses

CWE-256

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2025-2500