CVE-2025-0417 Details
Description
Lack of protection against brute force attacks in Valmet DNA visualization in DNA Operate. The possibility to make an arbitrary number of login attempts without any rate limit gives an attacker an increased chance of guessing passwords and then performing switching operations.
A brute force vulnerability exists in Valmet DNA Operate, allowing an unlimited number of login attempts without any rate limiting. This lack of protection increases the likelihood of password guessing, potentially leading to unauthorized access and the ability to perform switching operations.
Users can contact Valmet Automation Customer Service for the new version that addresses this vulnerability. Additionally, a properly configured firewall can help prevent unauthorized access from untrusted networks.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 1, 2025CISA-ADP
Assessed Apr 1, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.valmet.com/about-us/about/research-and-development/vulnerabilityadvisories/cve-2025-0417/ | National Cyber Security Centre Finland | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-307 | Improper Restriction of Excessive Authentication Attempts | National Cyber Security Centre Finland |
Affected Products
| Product | Versions |
|---|---|
| Valmet DNA Operate | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | National Cyber Security Centre Finland |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 1, 2025 | New CVE Received | National Cyber Security Centre Finland |
Volerion