Security Advisory

CVE-2025-43720

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-07-21 00:00:00
Last updated 2025-07-22 13:52:37
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Headwind MDM before 5.33.1 makes configuration details accessible to unauthorized users. The Configuration profile is exposed to the Observer user role, revealing the password requires to escape out of the MDM controlled device's profile.