CVE-2025-20640

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Feb 3, 2025
Updated: Feb 4, 2025
CWE ID 125

Summary

CVE-2025-20640 is a vulnerability affecting DA software, where a missing bounds check leads to a potential out-of-bounds read issue. This weakness could result in local information disclosure, requiring no additional execution privileges for attackers with physical access to the device. User interaction is necessary for exploitation, and the patch ID to mitigate this issue is ALPS09291146, with the internal reference being MSV-2059.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share