CVE-2025-3218

MEDIUM

I - Improper Certificate Validation

Title source: rule
STIX 2.1

Description

IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 is vulnerable to authentication and authorization attacks due to incorrect validation processing in IBM i Netserver. A malicious actor could use the weaknesses, in conjunction with brute force authentication attacks or to bypass authority restrictions, to access the server.

Scores

CVSS v3 5.4
EPSS 0.0010
EPSS Percentile 27.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-295
Status published
Products (5)
ibm/i 7.2
ibm/i 7.3
ibm/i 7.4
ibm/i 7.5
ibm/i 7.6
Published May 07, 2025
Tracked Since Feb 18, 2026