Security Advisory

CVE-2025-35978

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-06-12 06:05:00
Last updated 2025-06-12 13:04:50
Assigner jpcert
CVSS score 7.1
State PUBLISHED

Description

Improper restriction of communication channel to intended endpoints issue exists in UpdateNavi V1.4 L10 to L33 and UpdateNaviInstallService Service 1.2.0091 to 1.2.0125. If a local authenticated attacker send malicious data, an arbitrary registry value may be modified or arbitrary code may be executed.