CVE Database
/

CVE-2025-62577

Back to search

CVE-2025-62577

Published: Oct 20, 2025

Modified: Nov 3, 2025

PUBLISHED

CVSS v3.0

8.8

HIGH

Description

ETERNUS SF provided by Fsas Technologies Inc. contains an incorrect default permissions vulnerability. A low-privileged user with access to the management server may obtain database credentials, potentially allowing execution of OS commands with administrator privileges.

VendorProductVersions

Fsas Technologies Inc.

ETERNUS SF AdvancedCopy Manager Standard Edition (for Solaris 10/ 11)

affected
15.0/ 15.1/ 15.2/ 15.3/ 16.0/ 16.1/ 16.2/ 16.3/ 16.4/ 16.5/ 16.6/ 16.7/ 16.8/ 16.9/ 16.9.1

Fsas Technologies Inc.

ETERNUS SF Storage Cruiser (for Solaris 10/ 11)

affected
15.0/ 15.1/ 15.2/ 15.3/ 16.0/ 16.1/ 16.2/ 16.3/ 16.4/ 16.5/ 16.6/ 16.7/ 16.8/ 16.9/ 16.9.1

Fsas Technologies Inc.

ETERNUS SF AdvancedCopy Manager Standard Edition (for RHEL 7/ 8/ 9)

affected
16.2/ 16.3/ 16.4/ 16.5/ 16.6/ 16.7/ 16.8/ 16.9/ 16.9.1

Fsas Technologies Inc.

ETERNUS SF Expressn (for RHEL 7/ 8/ 9)

affected
16.2/ 16.3/ 16.4/ 16.5/ 16.6/ 16.7/ 16.8/ 16.9/ 16.9.1

Fsas Technologies Inc.

ETERNUS SF Storage Cruisern (for RHEL 7/ 8/ 9)

affected
16.2/ 16.3/ 16.4/ 16.5/ 16.6/ 16.7/ 16.8/ 16.9/ 16.9.1

Fsas Technologies Inc.

ETERNUS SF AdvancedCopy Manager Standard Edition (for Windows Server 2016/ 2019/ 2022)

affected
16.4/ 16.5/ 16.6/ 16.7/ 16.8/ 16.9/ 16.9.1

Fsas Technologies Inc.

ETERNUS SF Express (for Windows Server 2016/ 2019/ 2022)

affected
16.4/ 16.5/ 16.6/ 16.7/ 16.8/ 16.9/ 16.9.1

Fsas Technologies Inc.

ETERNUS SF Storage Cruiser (for Windows Server 2016/ 2019/ 2022)

affected
16.4/ 16.5/ 16.6/ 16.7/ 16.8/ 16.9/ 16.9.1

Weaknesses (CWE)

CVSS v3.0 Details

CVSS v3.0 Vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Attack Vector

Local

Attack Complexity

Low

Privileges Required

Low

User Interaction

None

Scope

Changed

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now