CVE-2025-59093
Last modified
CVE-2025-59093 is a high-severity vulnerability rated 8.5/10 on the CVSS scale. Exos 9300 instances are using a randomly generated database password to connect to the configured MSSQL server. The password is derived from static random values, which are concatenated to the hostname and a random string that can be read by every user from the registry. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
Exos 9300 instances are using a randomly generated database password to connect to the configured MSSQL server. The password is derived from static random values, which are concatenated to the hostname and a random string that can be read by every user from the registry. This allows an attacker to derive the database password and get authenticated access to the central exos 9300 database as the user Exos9300Common. The user has the roles ExosDialog and ExosDialogDotNet assigned, which are able to read most tables of the database as well as update and insert into many tables.
Metrics
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-59093?
How severe is CVE-2025-59093?
How do I fix CVE-2025-59093?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-59088If kdcproxy receives a request for a realm which does not ha…8.6
- CVE-2025-59089If an attacker causes kdcproxy to connect to an attacker-con…5.9
- CVE-2025-5909A vulnerability, which was classified as critical, was found…8.8
- CVE-2025-59090On the exos 9300 server, a SOAP API is reachable on port 800…9.3
- CVE-2025-59091Multiple hardcoded credentials have been identified, which a…9.3
- CVE-2025-59092An RPC service, which is part of exos 9300, is reachable on …8.7
- CVE-2025-59094A local privilege escalation vulnerability has been identifi…8.4
- CVE-2025-59095The program libraries (DLL) and binaries used by exos 9300 c…6.8
- CVE-2025-59096The default password for the extended admin user mode in the…4.6
- CVE-2025-59097The exos 9300 application can be used to configure Access Ma…9.3
- CVE-2025-59098The Access Manager is offering a trace functionality to debu…8.7
- CVE-2025-59099The Access Manager is using the open source web server Compa…8.8
Are you affected by CVE-2025-59093?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
