CVE-2025-20886

CVSS 3.1 Score 4.4 of 10 (medium)

Details

Published Feb 4, 2025
Updated: Feb 12, 2025
CWE ID 922

Summary

CVE-2025-20886 is a vulnerability affecting the softsim TA software prior to the SMR Jan-2025 Release 1. This issue arises due to the inclusion of sensitive information in test code. A local privileged attacker can exploit this vulnerability to obtain a test key, potentially gaining unauthorized access to protected data or functionality. This oversight in the testing environment could pose a significant risk to system security. Organizations using softsim TA are advised to upgrade to the latest release as soon as possible to mitigate this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share