CVE-2025-0509 is a medium-severity vulnerability affecting Sparkle versions prior to 2.6.4, as well as NetApp HCI Compute Node and OnCommand Workflow Automation. This flaw allows a highly privileged attacker on an adjacent network to bypass Sparkle's digital signature verification, enabling the replacement of legitimate signed updates with malicious payloads. While the CVSS score is 6.8, indicating significant impact (confidentiality, integrity, and availability), there is currently no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.6.4CPE matchmatch criteria | cpe:2.3:a:sparkle-project:sparkle:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:netapp:hci_compute_node:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:oncommand_workflow_automation:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.