CVE-2025-3321

CRITICAL

Predefined Administrative Account - Info Disclosure

Title source: llm
STIX 2.1

Description

A predefined administrative account is not documented and cannot be deactivated. This account cannot be misused from the network, only by local users on the server.

Scores

CVSS v4 9.4
EPSS 0.0010
EPSS Percentile 27.3%
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-798
Status published
Products (1)
B. Braun Melsungen AG/OnlineSuite 3.0
Published Jun 06, 2025
Tracked Since Feb 18, 2026