Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-30189

25
FAUCET Score

CVE-2025-30189 identifies a vulnerability in certain passdb/userdb drivers where, with caching enabled, user information is incorrectly cached, leading to subsequent logins being attributed to the wrong user; affected products are not specified. This high-severity vulnerability (CVSS 7.4) has a network attack vector and high attack complexity, potentially resulting in unauthorized access and significant impact on confidentiality and integrity. Despite its potential impact, there are currently no known public exploits, Metasploit modules, or Nuclei templates available, and it is not listed on the KEV catalog, indicating no active exploitation or significant community attention at this time.

Impacted Technologies

VendorProductVersion(s)CPE
Open-Xchange GmbHOX Dovecot Pro
>= 0, <= 2.4.0, >= 0, <= 3.1.0CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 3.1

7.4HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
2.2
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.55%
Probability of exploitation in next 30 days
EPSS Percentile
42.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0055 is in the 16th percentile among its peer group of 8,914 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (7)

denopatch availablevia llm_extracted
View patch
drupalpatch availablevia llm_extracted
View patch
freeswitchpatch availablevia llm_extracted
View patch
synologypatch availablevia llm_extracted
Fixed in: null
View patch
boschvendor investigatingvia llm_extracted
View patch
broadcomvendor investigatingvia llm_extracted
View patch
ubiquitivendor investigatingvia llm_extracted
View patch

Vendor Advisories (7)

drupalllm-drupal-722ed3a5ac0fea78

Using auth caching with oauth2 passdb, passwd passdb or userdb, or passwd userdb, causes the first lookup to be cached for all the lookups.

Oct 29, 2025
ubiquitillm-ubiquiti-4715cb5ac9a67359

Using auth caching with oauth2 passdb, passwd passdb or userdb, or passwd userdb, causes the first lookup to be cached for all the lookups.

Oct 29, 2025
synologyllm-synology-b8b1c692a858641d

Using auth caching with oauth2 passdb, passwd passdb or userdb, or passwd userdb, causes the first lookup to be cached for all the lookups.

Oct 29, 2025
denollm-deno-5ab03973d0194e27

Using auth caching with oauth2 passdb, passwd passdb or userdb, or passwd userdb, causes the first lookup to be cached for all the lookups.

Oct 29, 2025
broadcomllm-broadcom-04ddfaba5a81d147

CVE-2025-30189: Using auth caching with oauth2 passdb, passwd passdb or userdb, or passwd userdb, causes the first lookup to be cached for all the lookups.

Oct 29, 2025
freeswitchllm-freeswitch-02de95a539dca8b1

Using auth caching with oauth2 passdb, passwd passdb or userdb, or passwd userdb, causes the first lookup to be cached for all the lookups.

Oct 29, 2025
boschllm-bosch-85c00a2ea5bee9f0

CVE-2025-30189: Using auth caching with oauth2 passdb, passwd passdb or userdb, or passwd userdb, causes the first lookup to be cached for all the lookups.

Oct 29, 2025

References

seclists.org / fulldisclosure/2025/Oct/29
openwall.com / lists/oss-security/2025/10/29/4
documentation.open-xchange.com / dovecot/security/advisories/csaf/2026/oxdc-adv-2026-0001.json