CVE-2025-22375 Details
Description
An authentication bypass vulnerability was found in Videx's CyberAudit-Web. Through the exploitation of a logic flaw, an attacker could create a valid session without any credentials. This vulnerability has been patched in versions later than 9.5 and a patch has been made available to all instances of CyberAudit-Web, including the versions that are End of Maintenance (EOM). Anyone that requires support with the resolution of this issue can contact [email protected] for assistance.
A logic flaw in Videx's CyberAudit-Web prior to version 9.8.11 has been identified, allowing authentication bypass. This vulnerability enables an attacker to create a valid session without credentials. Videx has released a patch for this vulnerability, available to all CyberAudit-Web instances, including those that are End of Maintenance. Users needing assistance with the patch can contact Videx support.
Users are advised to update to the patched version of CyberAudit-Web. The patch has been made available to all instances, including those that are End of Maintenance.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 10, 2025CISA-ADP
Assessed Apr 10, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://csirt.divd.nl/CVE-2025-22375 | [email protected] | AdvisoryRemedy |
| https://csirt.divd.nl/DIVD-2024-00043/ | [email protected] | BundleTechnical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Videx CyberAudit-Web | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 10, 2025 | New CVE Received | [email protected] |
Volerion