CVE-2025-3838 Details
Description
An Improper Authorization vulnerability was identified in the EOL OVA based connect component which is deployed for installation purposes in the customer internal network. Under certain conditions, this could allow a bad actor to gain unauthorized access to the local db containing weakly hashed credentials of the installer. This EOL component was deprecated in September 2023 with end of support extended till January 2024.
A vulnerability allowing improper authorization has been identified in the EOL OVA based connect component, which is used for installation in the customer's internal network. This vulnerability could enable a bad actor to gain unauthorized access to the local database containing weakly hashed credentials of the installer, under certain conditions. The component was deprecated in September 2023, with support extended until January 2024.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 21, 2025CISA-ADP
Assessed Apr 21, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://saviynt.com/trust-compliance-security | Saviynt | Broken Link |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-327 | Use of a Broken or Risky Cryptographic Algorithm | Saviynt |
| CWE-863 | Incorrect Authorization | Saviynt |
Affected Products
| Product | Versions |
|---|---|
| EOL OVA based connect | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Saviynt |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 21, 2025 | New CVE Received | Saviynt |
Volerion