CVE-2025-27147

CVSS 3.1 Score 8.2 of 10 (high)

Details

Published Mar 25, 2025
Updated: Mar 27, 2025
CWE ID 73
CWE ID 22
CWE ID 552

Summary

CVE-2025-27147 is a vulnerability affecting the GLPI Inventory Plugin before version 1.5.0. This plugin, which is used by GLPI agents for network discovery and inventory, software deployment, VMWare ESX host remote inventory, and data collection, contains an access control issue. The flaw allows unauthorized access to sensitive information, potentially enabling attackers to conduct unauthorized actions within an affected system. Version 1.5.0 of the plugin addresses this vulnerability by implementing proper access controls.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share