Security Advisory

CVE-2025-42959

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-07-08 00:35:03
Last updated 2026-02-26 18:27:53
Assigner sap
State PUBLISHED

Description

An unauthenticated attacker may exploit a scenario where a Hashed Message Authentication Code (HMAC) credential, extracted from a system missing specific security patches, is reused in a replay attack against a different system. Even if the target system is fully patched, successful exploitation could result in complete system compromise, affecting confidentiality, integrity, and availability.