CVE-2025-8095 affects Progress OpenEdge's OECH1 prefix encoding mechanism, which is used to obfuscate values across the platform but has been determined to be cryptographically weak and unsuitable for enterprise use. The vulnerability impacts any system relying on OECH1 encoding for stored values, with Progress recommending immediate replacement with alternative supported prefix encodings that use symmetric encryption. While specific CVSS metrics are unavailable, the vulnerability carries a FAUCET Risk Score of 52.0/100 and an EPSS score of 0.00031, indicating relatively low exploit probability. The attack vector and technical complexity details are not documented, but the core issue is that OECH1-encoded values should be considered exploitable and require urgent remediation. There is currently no evidence of active exploitation in the wild, no public exploit code availability, and the vulnerability remains inactive on the Known Exploited Vulnerabilities (KEV) catalog, suggesting limited immediate community attention or threat actor focus.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Progress Software Corporation | OpenEdge | >= 12.2.0, <= 12.2.18, >= 12.8.0, <= 12.8.9CNA affecteddefault affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:D/RE:M/U:Red
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.