CVE-2025-62577 Details
Description
ETERNUS SF provided by Fsas Technologies Inc. contains an incorrect default permissions vulnerability. A low-privileged user with access to the management server may obtain database credentials, potentially allowing execution of OS commands with administrator privileges.
A vulnerability exists in ETERNUS SF products by Fsas Technologies Inc., related to incorrect default permissions. This issue affects several versions of ETERNUS SF AdvancedCopy Manager Standard Edition, ETERNUS SF Express, and ETERNUS SF Storage Cruiser, across different platforms including Oracle Solaris, Red Hat Enterprise Linux, and Windows Server. The vulnerability allows a low-privileged user with access to the management server to obtain database credentials, which could be used to execute operating system commands with administrator privileges.
Users can apply the patch available through the ETERNUS SF Support Desk. Instructions for downloading and applying the patch are provided on the Fsas Technologies website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 20, 2025CISA-ADP
Assessed Oct 20, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-276 | Incorrect Default Permissions | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Fsas Technologies ETERNUS SF AdvancedCopy Manager Standard Edition | All versions |
CPE
Remediation
| |
| Fsas Technologies ETERNUS SF Storage Cruiser | All versions |
CPE
Remediation
| |
| Fsas Technologies ETERNUS SF Express | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 3, 2025 | CVE Modified | CVE |
| Oct 20, 2025 | New CVE Received | [email protected] |
Volerion