CVE-2025-32985

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Apr 25, 2025
Updated: Apr 29, 2025
CWE ID 798

Summary

CVE-2025-32985 is a vulnerability affecting NETSCOUT nGeniusONE versions before 6.4.0. The issue arises due to hardcoded credentials found in JAR files, which can be easily accessed by attackers. This allows unauthorized access to nGeniusONE systems, potentially leading to data breaches and other malicious activities. The presence of these hardcoded credentials significantly increases the security risk for organizations using the affected version of the software. It is highly recommended that users upgrade to the latest version to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share