CVE-2025-62577
Published: Oct 20, 2025
Modified: Nov 3, 2025
CVSS v3.0
8.8
Description
ETERNUS SF provided by Fsas Technologies Inc. contains an incorrect default permissions vulnerability. A low-privileged user with access to the management server may obtain database credentials, potentially allowing execution of OS commands with administrator privileges.
| Vendor | Product | Versions |
|---|---|---|
Fsas Technologies Inc. | ETERNUS SF AdvancedCopy Manager Standard Edition (for Solaris 10/ 11) | affected 15.0/ 15.1/ 15.2/ 15.3/ 16.0/ 16.1/ 16.2/ 16.3/ 16.4/ 16.5/ 16.6/ 16.7/ 16.8/ 16.9/ 16.9.1 |
Fsas Technologies Inc. | ETERNUS SF Storage Cruiser (for Solaris 10/ 11) | affected 15.0/ 15.1/ 15.2/ 15.3/ 16.0/ 16.1/ 16.2/ 16.3/ 16.4/ 16.5/ 16.6/ 16.7/ 16.8/ 16.9/ 16.9.1 |
Fsas Technologies Inc. | ETERNUS SF AdvancedCopy Manager Standard Edition (for RHEL 7/ 8/ 9) | affected 16.2/ 16.3/ 16.4/ 16.5/ 16.6/ 16.7/ 16.8/ 16.9/ 16.9.1 |
Fsas Technologies Inc. | ETERNUS SF Expressn (for RHEL 7/ 8/ 9) | affected 16.2/ 16.3/ 16.4/ 16.5/ 16.6/ 16.7/ 16.8/ 16.9/ 16.9.1 |
Fsas Technologies Inc. | ETERNUS SF Storage Cruisern (for RHEL 7/ 8/ 9) | affected 16.2/ 16.3/ 16.4/ 16.5/ 16.6/ 16.7/ 16.8/ 16.9/ 16.9.1 |
Fsas Technologies Inc. | ETERNUS SF AdvancedCopy Manager Standard Edition (for Windows Server 2016/ 2019/ 2022) | affected 16.4/ 16.5/ 16.6/ 16.7/ 16.8/ 16.9/ 16.9.1 |
Fsas Technologies Inc. | ETERNUS SF Express (for Windows Server 2016/ 2019/ 2022) | affected 16.4/ 16.5/ 16.6/ 16.7/ 16.8/ 16.9/ 16.9.1 |
Fsas Technologies Inc. | ETERNUS SF Storage Cruiser (for Windows Server 2016/ 2019/ 2022) | affected 16.4/ 16.5/ 16.6/ 16.7/ 16.8/ 16.9/ 16.9.1 |
Weaknesses (CWE)
CVSS v3.0 Details
CVSS v3.0 Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now