CVE-2025-43720
Last modified
CVE-2025-43720 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Headwind MDM before 5.33.1 makes configuration details accessible to unauthorized users. The Configuration profile is exposed to the Observer user role, revealing the password requires to escape out of the MDM controlled device's profile.. EPSS estimates a 0.35% chance of exploitation in the next 30 days.
Description
Headwind MDM before 5.33.1 makes configuration details accessible to unauthorized users. The Configuration profile is exposed to the Observer user role, revealing the password requires to escape out of the MDM controlled device's profile.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| H-Mdm | Headwind Mdm | < 5.33.1 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-43720?
How severe is CVE-2025-43720?
How do I fix CVE-2025-43720?
Are you affected by CVE-2025-43720?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
