AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2025-3838

UNKNOWN · CVSS N/A EPSS 0.13%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-04-21 · Last synced 2026-08-04

CyberRota Analysis

This vulnerability has an unknown severity rating. See the original NVD description below for full technical details.

CVE
CVE-2025-3838
Severity
UNKNOWN
CVSS
N/A
EPSS
0.13%

Original NVD Description

An Improper Authorization vulnerability was identified in the EOL OVA based connect component which is deployed for installation purposes in the customer internal network. Under certain conditions, this could allow a bad actor to gain unauthorized access to the local db containing weakly hashed credentials of the installer. This EOL component was deprecated in September 2023 with end of support extended till January 2024.