CVE-2025-0619 Details
Description
Unsafe password recovery from configuration in M-Files Server before 25.1 allows a highly privileged user to recover external connector passwords
A vulnerability in M-Files Server versions prior to 25.1.14445.5 allows highly privileged users, such as system or vault administrators, to recover passwords for external connectors. This issue arises from an unsafe password recovery mechanism in the server's configuration. While these administrators can already set the passwords, the recovery feature is not typically allowed. It's important to note that this vulnerability does not impact other user types or administrative passwords. The issue is particularly relevant in environments with multiple admin users who have different levels of access to external systems connected via EOT connectors, which are not enabled by default.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 23, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://empower.m-files.com/security-advisories/CVE-2025-0619 | [email protected] | |
| https://product.m-files.com/security-advisories/cve-2025-0619/ | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-522 | Insufficiently Protected Credentials | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| m-files m-files server | < 25.1.14445.5 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 23, 2026 | CVE Modified | [email protected] |
| Oct 3, 2025 | Initial Analysis | [email protected] |
| Jan 23, 2025 | New CVE Received | [email protected] |