CVE-2025-0509
HIGHSparkle < 2.6.4 - Unauthenticated Update Replacement via Signature Bypass
Title source: llmDescription
A security issue was found in Sparkle before version 2.6.4. An attacker can replace an existing signed update with another payload, bypassing Sparkle’s (Ed)DSA signing checks.
References (3)
Core 3
Core References
Issue Tracking, Patch
https://github.com/sparkle-project/Sparkle/pull/2550
Vendor Advisory
https://security.netapp.com/advisory/ntap-20250124-0008/
Scores
CVSS v3
7.3
EPSS
0.0085
EPSS Percentile
53.2%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-552
Status
published
Products (4)
netapp/hci_compute_node
netapp/oncommand_workflow_automation
sparkle-project/sparkle
< 2.6.4
SwiftURL/github.com/sparkle-project/Sparkle
0 - 2.6.4SwiftURL
Published
Feb 04, 2025
Tracked Since
Feb 18, 2026