CVE-2025-43017
Last modified
CVE-2025-43017 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. HP ThinPro 8.1 System management application failed to verify user's true id. HP has released HP ThinPro 8.1 SP8, which includes updates to mitigate potential vulnerabilities.. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
HP ThinPro 8.1 System management application failed to verify user's true id. HP has released HP ThinPro 8.1 SP8, which includes updates to mitigate potential vulnerabilities.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Hp | Thinpro | 8.1 | Sp2 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-43017?
How severe is CVE-2025-43017?
How do I fix CVE-2025-43017?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-43011Under certain conditions, SAP Landscape Transformation's PCL…7.7
- CVE-2025-43012In JetBrains Toolbox App before 2.6 command injection in SSH…9.8
- CVE-2025-43013In JetBrains Toolbox App before 2.6 unencrypted credential t…7.5
- CVE-2025-43014In JetBrains Toolbox App before 2.6 the SSH plugin establish…6.5
- CVE-2025-43015In JetBrains RubyMine before 2025.1 remote Interpreter overw…6.5
- CVE-2025-43016In JetBrains Rider before 2025.1.2 custom archive unpacker a…7.5
- CVE-2025-43018Certain HP LaserJet Pro printers may be vulnerable to inform…5.3
- CVE-2025-43019A potential security vulnerability has been identified in th…7.8
- CVE-2025-4302The Stop User Enumeration WordPress plugin before version 1.…5.3
- CVE-2025-43020A potential command injection vulnerability has been identif…6.8
- CVE-2025-43021A potential security vulnerability has been identified in th…5.7
- CVE-2025-43022A potential SQL injection vulnerability has been identified …7.2
Are you affected by CVE-2025-43017?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
