CVE-2025-25060

HIGH

AssetView and AssetView CLOUD < 13.2.4.3408 and < 13.3.4.3004 - Unauthenticated Arbitrary File Read and Delete

Title source: llm
STIX 2.1

Description

Missing authentication for critical function vulnerability exists in AssetView and AssetView CLOUD. If exploited, the files on the server where the product is running may be obtained and/or deleted by a remote unauthenticated attacker.

References (2)

Core 2
Core References
Third Party Advisory
https://jvn.jp/en/jp/JVN26321838/

Scores

CVSS v3 8.2
EPSS 0.0044
EPSS Percentile 34.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-306
Status published
Products (3)
Hammock Corporation/AssetView prior to Ver 13.2.4.3408 (13.2.4O)
Hammock Corporation/AssetView CLOUD prior to Ver 13.2.4.3408 (13.2.4O)
Hammock Corporation/AssetView CLOUD prior to Ver 13.3.4.3004 (13.3.4K)
Published Apr 02, 2025
Tracked Since Feb 18, 2026