CVE-2025-12381 is an Improper Privilege Management vulnerability in AlgoSec Firewall Analyzer on Linux (64-bit), affecting versions A33.0 and A33.10. A local attacker can exploit this flaw to escalate privileges by injecting parameters into a sudoers-approved command. With a CVSS score of 7.8 (High), this vulnerability allows for complete compromise of confidentiality, integrity, and availability with low attack complexity and no user interaction required. There is currently no public exploit code available, no evidence of active exploitation, and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
a33.0CPE matchmatch criteria | cpe:2.3:a:algosec:firewall_analyzer:a33.0:*:*:*:*:*:*:* | ||
a33.10CPE matchmatch criteria | cpe:2.3:a:algosec:firewall_analyzer:a33.10:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:L/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:X/RE:L/U:Amber
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.