CVE-2025-2538

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Mar 20, 2025
Updated: Apr 1, 2025
CWE ID 798

Summary

CVE-2025-2538 is a hardcoded credential vulnerability affecting Esri Portal for ArcGIS versions 11.4 and below. This issue arises from a specific deployment pattern and grants remote authenticated attackers the ability to elevate their privileges and obtain administrative access to the system. Successful exploitation of this weakness could lead to significant security implications, including unauthorized system modification or data exfiltration. Organizations utilizing the affected versions are strongly encouraged to apply the available patches to mitigate the risk of this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Esri Portal for ArcGIS

Affected Vendors

  • Esri