CVE-2025-13774 Details
Description
A vulnerability exists in Progress Flowmon ADS versions prior to 12.5.4 and 13.0.1 where an SQL injection vulnerability allows authenticated users to execute unintended SQL queries and commands.
In Progress Flowmon ADS, an SQL injection vulnerability has been identified in versions prior to 12.5.4 and 13.0.1. This vulnerability allows authenticated users to execute unintended SQL queries and commands, potentially leading to unauthorized privilege escalation and compromising the integrity and confidentiality of the affected Flowmon appliance.
Users are advised to upgrade to Flowmon ADS version 12.5.4 or 13.0.1. Upgrade packages are available through the Progress Community. Note that upgrading to a patched release using the full installer is the only way to address this vulnerability, and the upgrade will cause a temporary outage of the system.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://community.progress.com/s/article/Flowmon-ADS-CVE-2025-13774 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| progress flowmon anomaly detection system | >= 12.0.0, <= 12.5.4 >= 13.0.0, <= 13.0.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 5, 2026 | Initial Analysis | [email protected] |
| Jan 13, 2026 | New CVE Received | [email protected] |