We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-22375

Authentication Bypass in CyberAudit-Web



Description

An authentication bypass vulnerability was found in Videx's CyberAudit-Web. Through the exploitation of a logic flaw, an attacker could create a valid session without any credentials. This vulnerability has been patched in versions later than 9.5 and a patch has been made available to all instances of CyberAudit-Web, including the versions that are End of Maintenance (EOM). Anyone that requires support with the resolution of this issue can contact support@videx.com for assistance.

Reserved 2025-01-03 | Published 2025-04-10 | Updated 2025-04-10 | Assigner DIVD


CRITICAL: 9.3CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/S:N/AU:Y/R:A/V:D/RE:L/U:Green

Problem types

CWE-287 Improper Authentication

Product status

Default status
unaffected

<= 9.5
affected

Credits

Hidde Smit (DIVD) finder

Wietse Boonstra (DIVD) finder

Max van der Horst (DIVD) analyst

References

csirt.divd.nl/CVE-2025-22375 third-party-advisory

csirt.divd.nl/DIVD-2024-00043/ third-party-advisory

cve.org (CVE-2025-22375)

nvd.nist.gov (CVE-2025-22375)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-22375

Support options

Helpdesk Chat, Email, Knowledgebase