CVE-2025-2888
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Mar 27, 2025
Updated: Mar 28, 2025
CWE ID 79
Summary
CVE-2025-2888 is a vulnerability affecting snapshot rollbacks in certain versions of the Tough data integrity tool. The issue lies in the incorrect caching of timestamp metadata during rollbacks. If the client relies on the cache for the next update, the update timestamp validation will fail, leading to the prevention of further updates until the cache is cleared. To mitigate this risk, users must upgrade to Tough version 0.20.0 or later and ensure any forked or derivative code is patched with the new fixes.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.