CVE-2025-0417

HIGH

Valmet DNA visualization - Info Disclosure

Title source: llm
STIX 2.1

Description

Lack of protection against brute force attacks in Valmet DNA visualization in DNA Operate. The possibility to make an arbitrary number of login attempts without any rate limit gives an attacker an increased chance of guessing passwords and then performing switching operations.

Scores

CVSS v4 7.0
EPSS 0.0010
EPSS Percentile 27.3%
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/AU:Y/R:A/V:D/RE:L/U:Green

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-307
Status published
Products (1)
Valmet/Valmet DNA C2007 - C2024
Published Apr 01, 2025
Tracked Since Feb 18, 2026