VulnerabilityDeferred
CVE-2025-15581
Successful exploitation could result in Privilege Escalation, potentially allowing full administrative access.
MEDIUM 4.7EPSS 0.41%
Does this matter?
Lower severity and a low EPSS score (0.41%). Track it; it rarely justifies an emergency change on its own.
Description
Orthanc versions before 1.12.10 are affected by an authorisation logic flaw in the application's HTTP Basic Authentication implementation. Successful exploitation could result in Privilege Escalation, potentially allowing full administrative access.
- CVSS 4.0
- 4.7 MEDIUMCVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.41% probability · 34th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Source
- ab69c47f-b95e-4bf2-b2d9-4b1fd1b24b4a
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.