CVE 6.7 MEDIUM

Privilege escalation via writable configuration files in Progress Flowmon_CVE-2025-11906

6.7 / 10
MEDIUM
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Description

A vulnerability exists in Progress Flowmon versions prior 12.5.6 where certain system configuration files have incorrect file permissions, allowing a user with access to the default flowmon system user account used for SSH access to potentially escalate privileges to root during service initialization.

Basic Information

ID CVE-2025-11906
Source ProgressSoftware
Published Oct 30, 2025 at 07:39

Affected Product

Vendor Progress Software
Product Flowmon
Version Flowmon 12 versions prior to 12.5.6
Affected Versions Progress Software Flowmon Flowmon 12 versions prior to 12.5.6

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.