A vulnerability exists in Asset Suite for an authenticated user to manipulate the content of performance related log data or to inject crafted data in logfile for potentially carrying out further malicious attacks. Performance logging is typically enabled for troubleshooting purposes while resolving application performance related issues.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 30 Sep 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 30 Sep 2025 12:30:00 +0000

Type Values Removed Values Added
Description A vulnerability exists in Asset Suite for an authenticated user to manipulate the content of performance related log data or to inject crafted data in logfile for potentially carrying out further malicious attacks. Performance logging is typically enabled for troubleshooting purposes while resolving application performance related issues.
Weaknesses CWE-117
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Hitachi Energy

Published:

Updated: 2025-09-30T13:04:07.996Z

Reserved: 2025-09-10T11:07:55.536Z

Link: CVE-2025-10217

cve-icon Vulnrichment

Updated: 2025-09-30T13:04:04.885Z

cve-icon NVD

Status : Received

Published: 2025-09-30T13:15:48.370

Modified: 2025-09-30T13:15:48.370

Link: CVE-2025-10217

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.