CVE-2025-41064

CRITICAL

GTT OpenSIAC - Improper Authentication via Cl@ve Impersonation

Title source: llm
STIX 2.1

Description

Incorrect authentication vulnerability in OpenSIAC, which could allow an attacker to impersonate a person using Cl@ve as an authentication method.

Scores

CVSS v4 9.3
EPSS 0.0044
EPSS Percentile 34.6%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-287
Status published
Products (1)
GTT/OpenSIAC 1.0
Published Oct 02, 2025
Tracked Since Feb 18, 2026