CVE-2025-30000

CVSS 3.1 Score 6.7 of 10 (medium)

Details

Published Apr 8, 2025
CWE ID 295

Summary

CVE-2025-30000: A critical vulnerability was discovered in Siemens License Server (SLS) versions prior to V4.3. The issue lies in the application's failure to adequately manage user permissions. This flaw presents an opportunity for a low-privileged attacker to exploit the vulnerability and escalate their privileges, potentially gaining unauthorized access to sensitive information or system functions. This vulnerability poses a significant risk and requires immediate attention from Siemens License Server users. It is strongly recommended that they upgrade to the latest version as soon as possible to mitigate the threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Citrix License Server

Affected Vendors

  • Citrix Systems