Description
Certain functionality within GMOD Apollo does not require authentication when passed with an administrative username
Published: 2025-03-05
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

GMOD recommends users to update to the newest Version 2.8.0 https://github.com/GMOD/Apollo .

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-6196 Certain functionality within GMOD Apollo does not require authentication when passed with an administrative username
History

Wed, 05 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 05 Mar 2025 00:15:00 +0000

Type Values Removed Values Added
Description Certain functionality within GMOD Apollo does not require authentication when passed with an administrative username
Title GMOD Apollo Missing Authentication for Critical Function
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-03-05T15:07:16.136Z

Reserved: 2025-02-27T17:04:46.527Z

Link: CVE-2025-24924

cve-icon Vulnrichment

Updated: 2025-03-05T15:07:08.823Z

cve-icon NVD

Status : Deferred

Published: 2025-03-05T00:15:38.423

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-24924

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses