# CVE-2025-22492

## Summary

- **CVE ID:** CVE-2025-22492
- **Severity:** MEDIUM
- **CVSS Score:** 6.3 (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L)
- **CWE:** CWE-922
- **Published:** Feb 28, 2025
- **Last Modified:** Mar 13, 2026

## Description

The connection string visible to users with access to FRSCore database on Foreseer Reporting Software (FRS) VM, this
string can be used for gaining administrative access to the 4crXref database. This vulnerability has been resolved in the latest version 1.5.100 of FRS.

## Affected Products

- Eaton — Foreseer Reporting Software (FRS) (0)

## References

- [CNA](https://www.eaton.com/content/dam/eaton/company/news-insights/cybersecurity/security-bulletins/etn-va-2024-1009.pdf)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.16%
- **EPSS Percentile:** 5.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-12._