CVE-2025-24921
Improper neutralization for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platform may allow an unauthenticated user to potentially enable information disclosure via adjacent access.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.9
- CVSS vector
- CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.20%
- CWE
- CWE-707
- Published
- 2025-08-12
- Last modified
- 2026-03-12
Affected products
- n/a Edge Orchestrator software
Weakness type
Related vulnerabilities
- CVE-2026-20278 — Cisco IOS XR Software Security Hardening Release: September 2026
- CVE-2026-76993 — GreyDGL PentestGPT Web-Page Crawling injection
- CVE-2026-18613 — GL-iNet GL-MT3000 plugins.so Native Plugin glc plugins.set_config injection
- CVE-2026-4249 — Denial of Service via Malicious JSON Payloads in Throttling Events in Multiple WSO2 Products Causing Persistent Service Disruption
- CVE-2026-11457 — erzhongxmu JeeWMS JimuReport test-connection Endpoint testConnection injection
- CVE-2026-10661 — ahujasid blender-mcp server.py open injection
- CVE-2026-10223 — NousResearch hermes-agent memory_tool.py _scan_memory_content injection
- CVE-2026-10222 — NousResearch hermes-agent config.py _sanitize_env_lines injection