CVE-2025-12737
8.4
Vector
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Exploitability: 1.7 / Impact: 6.0
Source: ed10eef1-636d-4fbe-9993-6890dfa878f8 (Secondary)
Description
The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This oversight allows a malicious actor with administrative privileges to inject and execute arbitrary code remotely.
Successful exploitation enables a threat actor with administrative privileges and Carbon Console access to execute remote arbitrary code through specific administrative operations, leading to a complete compromise of the affected system.
Affected (26)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 4.5.0 to 4.5.0.36 | |
| From 3.1.0 to 3.1.0.349 | |
| From 5.10.0 to 5.10.0.378 | |
| From 5.10.0 to 5.10.0.369 | |
| From 2.0.0 to 2.0.0.398 | |
| From 2.0.0 to 2.0.0.418 | |
| From 4.5.0 to 4.5.0.34 | |
| From 4.5.0 to 4.5.0.34 |
References (1)
Source: ed10eef1-636d-4fbe-9993-6890dfa878f8
PatchVendor Advisory
Timeline
No history available yet.