CVE-2025-24340

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Apr 30, 2025
Updated: May 2, 2025
CWE ID 916

Summary

CVE-2025-24340 is a vulnerability discovered in the users configuration file of ctrlX OS. This issue permits a remote, authenticated and low-privileged attacker to gain access to the plaintext passwords of other users. The attacker can exploit this vulnerability to compromise multiple user accounts, potentially leading to unauthorized access and data breaches. The impact of this flaw is significant as it undermines the security of user authentication in the affected system. It is essential for organizations using ctrlX OS to apply the necessary patches or updates to mitigate this vulnerability and protect their sensitive information.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share