Client-Side Enforcement of Server-Side Security (CWE-602) in the Command Centre Server allows a privileged operator to enter invalid competency data, bypassing expiry checks.
This issue affects Command Centre Server:
9.30 prior to vEL9.30.2482 (MR2), 9.20 prior to vEL9.20.2819 (MR4), 9.10 prior to vEL9.10.3672 (MR7), all versions of 9.00 and prior.
This issue affects Command Centre Server:
9.30 prior to vEL9.30.2482 (MR2), 9.20 prior to vEL9.20.2819 (MR4), 9.10 prior to vEL9.10.3672 (MR7), all versions of 9.00 and prior.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 23 Oct 2025 03:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Client-Side Enforcement of Server-Side Security (CWE-602) in the Command Centre Server allows a privileged operator to enter invalid competency data, bypassing expiry checks. This issue affects Command Centre Server: 9.30 prior to vEL9.30.2482 (MR2), 9.20 prior to vEL9.20.2819 (MR4), 9.10 prior to vEL9.10.3672 (MR7), all versions of 9.00 and prior. | |
Weaknesses | CWE-602 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Gallagher
Published:
Updated: 2025-10-23T03:38:22.200Z
Reserved: 2025-06-17T02:18:59.253Z
Link: CVE-2025-41402

No data.

Status : Received
Published: 2025-10-23T04:16:40.257
Modified: 2025-10-23T04:16:40.257
Link: CVE-2025-41402

No data.

No data.