CVE-2025-54767 Details
Description
An authenticated, read-only user can kill any processes running on the Xormon Original virtual appliance as the lpar2rrd user.
A denial-of-service vulnerability has been identified in Xorux LPAR2RRD versions through 8.04, running on Rocky Linux 8.10. The issue allows an authenticated, read-only user to terminate any processes on the Xormon Original virtual appliance as the lpar2rrd user. Exploitation of this vulnerability can disrupt services by stopping the web server, the xormon.war web application, or the lpar2rrd-daemon process.
Users are advised to upgrade to Xorux LPAR2RRD version 8.05, which addresses this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 29, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://seclists.org/fulldisclosure/2025/Jul/17 | CVE | |
| https://korelogic.com/Resources/Advisories/KL-001-2025-014.txt | KoreLogic | ExploitThird Party Advisory |
| https://lpar2rrd.com/note800.php | KoreLogic | Release Notes |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-648 | Incorrect Use of Privileged APIs | KoreLogic |
Affected Products
| Product | Versions |
|---|---|
| xorux lpar2rrd | <= 8.04 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | KoreLogic |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 3, 2025 | CVE Modified | CVE |
| Oct 9, 2025 | Initial Analysis | [email protected] |
| Jul 29, 2025 | CVE Modified | CISA-ADP |
| Jul 29, 2025 | New CVE Received | KoreLogic |