CVE-2025-46412
CRITICALCVSS 9.8/10EPSS 0.55%
Last modified
CVE-2025-46412 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Affected Vertiv products do not properly protect webserver functions that could allow an attacker to bypass authentication.. EPSS estimates a 0.55% chance of exploitation in the next 30 days.
Description
Affected Vertiv products do not properly protect webserver functions that could allow an attacker to bypass authentication.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-46412?
Affected Vertiv products do not properly protect webserver functions that could allow an attacker to bypass authentication.
How severe is CVE-2025-46412?
CVE-2025-46412 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 0.55% probability of exploitation in the next 30 days.
How do I fix CVE-2025-46412?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-46407A memory corruption vulnerability exists in the BMPv3 Palett…8.8
- CVE-2025-46408An issue was discovered in the methods push.lite.avtech.com.…9.8
- CVE-2025-46409Inadequate encryption strength issue exists in SS1 Ver.16.0.…8.7
- CVE-2025-4641Improper Restriction of XML External Entity Reference vulner…9.3
- CVE-2025-46410A cross-site scripting (xss) vulnerability exists in the man…6.1
- CVE-2025-46411A stack-based buffer overflow vulnerability exists in the MF…9.8
- CVE-2025-46413Use of password hash with insufficient computational effort …5.3
- CVE-2025-46414The affected product does not limit the number of attempts f…9.2
- CVE-2025-46415A race condition in the Nix, Lix, and Guix package managers …3.2
- CVE-2025-46416The Nix, Lix, and Guix package managers allow a bypass of bu…2.9
- CVE-2025-46417The unsafe globals in Picklescan before 0.0.25 do not includ…7.5
- CVE-2025-46418Westermo WeOS 5.x starting from 5.24 allows OS command injec…7.6
Are you affected by CVE-2025-46412?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
