CVE-2025-9317

HIGH

Edge Project <unknown - Info Disclosure

Title source: llm
STIX 2.1

Description

The vulnerability, if exploited, could allow a miscreant with read access to Edge Project files or Edge Offline Cache files to reverse engineer Edge users' app-native or Active Directory passwords through computational brute-forcing of weak hashes.

Scores

CVSS v3 8.4
EPSS 0.0001
EPSS Percentile 0.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-327
Status published
Products (1)
AVEVA/Edge < Versions 2023 R2
Published Nov 15, 2025
Tracked Since Feb 18, 2026