CVE-2025-3129

CVSS 3.1 Score 4.8 of 10 (medium)

Details

Published Apr 2, 2025
Updated: Apr 15, 2025
CWE ID 307

Summary

CVE-2025-3129 is a vulnerability affecting Drupal Access code versions prior to 2.0.4. The issue involves a failure to properly restrict excessive authentication attempts, making it susceptible to Brute Force attacks. An attacker can exploit this vulnerability by making repeated login attempts to gain unauthorized access to the system. This weakness could potentially lead to serious security consequences, including data breaches or unauthorized system control. System administrators are advised to update their Drupal Access code to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Access Code

Affected Vendors

  • Drupal Association