CVE-2025-2500 is a high-severity vulnerability (CVSS 7.4) affecting the SOAP Web services of Asset Suite versions, allowing unauthorized access and potentially expanding the window for password attacks. The attack vector is network-based with high attack complexity, requiring no user interaction, and could lead to high confidentiality and integrity impacts. While there is no known exploit code available in Metasploit, Nuclei, or ExploitDB, and it's not listed in CISA's KEV catalog, the vulnerability has garnered some community discussion and media coverage, including an article from Infosecurity Magazine.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Hitachi Energy | Asset Suite | 9.6.4.4, 9.7CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.