Description
A security issue was found in Sparkle before version 2.6.4. An attacker can replace an existing signed update with another payload, bypassing Sparkle’s (Ed)DSA signing checks.
Scores
CVSS v3
7.3
EPSS
0.0007
EPSS Percentile
21.5%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-552
Status
published
Products (4)
netapp/hci_compute_node
netapp/oncommand_workflow_automation
sparkle-project/sparkle
< 2.6.4
SwiftURL/github.com/sparkle-project/Sparkle
0 - 2.6.4SwiftURL
Published
Feb 04, 2025
Tracked Since
Feb 18, 2026