Security Advisory

CVE-2025-5485

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-06-12 20:05:35
Last updated 2025-06-12 20:14:57
Assigner icscert
State PUBLISHED

Description

User names used to access the web management interface are limited to the device identifier, which is a numerical identifier no more than 10 digits. A malicious actor can enumerate potential targets by incrementing or decrementing from known identifiers or through enumerating random digit sequences.