# CVE-2025-2500

## Summary

- **CVE ID:** CVE-2025-2500
- **Severity:** CRITICAL
- **CVSS Score:** 9.1 (CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-256
- **Published:** May 30, 2025
- **Last Modified:** Mar 12, 2026

## Description

A vulnerability exists in the SOAP Web services of the Asset 
Suite versions listed below. If successfully exploited, an attacker 
could gain unauthorized access to the product and the time window of a possible password attack could be expanded.

## Affected Products

- Hitachi Energy — Asset Suite (9.6.4.4)
- Hitachi Energy — Asset Suite (9.7)

## References

- [CNA](https://publisher.hitachienergy.com/preview?DocumentID=8DBD000212&LanguageCode=en&DocumentPartId=&Action=Launch)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.38%
- **EPSS Percentile:** 31.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._