CVE-2025-21403

CVSS 3.1 Score 6.4 of 10 (medium)

Details

Published Jan 14, 2025
CWE ID 863

Summary

CVE-2025-21403 is an Information Disclosure vulnerability affecting On-Premises Data Gateway. Successful exploitation allows attackers to gain unauthorized access to sensitive data, potentially compromising the security of an organization's network. The vulnerability arises from insufficient data validation and access control checks. An attacker can leverage this weakness to access data that should be restricted, potentially resulting in data breaches or further unauthorized actions. Organizations using On-Premises Data Gateway are advised to apply the available patch as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share