cvemon logocvemon logo

Activity

Trending

CVE-2025-32408

Published Apr 21, 2025

Last updated 2 months ago

CVSS low 2.5
  1. Overview

  2. Scores

  3. Weaknesses

  4. Social media

  5. References

Overview

Description
In Soffid Console 3.6.31 before 3.6.32, authorization to use the pam service is mishandled.
Source
cve@mitre.org
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
2.5
Impact score
1.4
Exploitability score
1
Vector string
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Severity
LOW

Weaknesses

cve@mitre.org
CWE-863

Social media

Hype score
Not currently trending
  1. ๐Ÿšจ CVE-2025-32408 ๐Ÿ”ด HIGH (8.5) ๐Ÿข Soffid - IAM ๐Ÿ—๏ธ 3.5.38 ๐Ÿ”— https://t.co/md4fgJ4H0y #CyberCron #VulnAlert #InfoSec https://t.co/sdOxzsgoHj

    @cybercronai

    21 Apr 2025

    12 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. New post from https://t.co/uXvPWJy6tj (CVE-2025-32408 | Soffid IAM Console 3.5.38 Java Object authorization) has been published on https://t.co/64P1VCWn7P

    @WolfgangSesin

    21 Apr 2025

    12 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. CVE-2025-32408 In Soffid Console 3.5.38 before 3.5.39, necessary checks were not applied to some Java objects. A malicious agent could possibly execute arbitrary code in the Sync Seโ€ฆ https://t.co/IIXIOSfAwX

    @CVEnew

    21 Apr 2025

    522 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

References

Sources include official advisories and independent security research.

  • https://nvd.nist.gov/vuln/detail/CVE-2025-32408
  • https://bookstack.soffid.com/books/security-advisories/page/cve-2025-32408
TRY INTRUDER
Intruder logo

ยฉ 2025 Intruder Systems Ltd.

AboutPrivacySitemapFeeds