CVE-2025-20948

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Apr 8, 2025

Summary

CVE-2025-20948 is a vulnerability affecting cdsp frame secfr trustlet in enrollment processes before the SMR Apr-2025 Release 1. This issue permits local privileged attackers to read out-of-bounds memory, potentially leading to the disclosure of sensitive information. The vulnerability occurs due to an out-of-bounds read condition, allowing attackers to access memory beyond its intended boundaries. Successful exploitation of this vulnerability could result in significant data leakage, highlighting the importance of applying the SMR Apr-2025 Release 1 patch as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share